Improper access control in Webform REST - CVE-2026-96391

 

Improper access control in Webform REST - CVE-2026-96391

Published: September 25, 2026


Vulnerability identifier: #VU152222
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-96391
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to the affected module does not sufficiently check permission to webform and webform submission entities when retrieving webform elements or fields. A remote user can view unauthorized webform elements and submission data.


Affected software

Webform REST

How to mitigate CVE-2026-96391

Install updates from vendor's website.

Webform REST - update to 4.2.1

External References

Related Security Bulletins