CVE-2026-96366 in Drupal Webform: managed file access bypass
An access bypass flaw, CVE-2026-96366 (12/25), was found in Drupal's Webform module: a user with submission rights could read managed files they were not authorized to view. Webform < 6.2.12 and 6.3.0–6.3.1 are affected; fixes are 6.2.12 and 6.3.1.
- Affected: Webform < 6.2.12 and 6.3.0–6.3.1; fixed in 6.2.12 and 6.3.1
- Rated 12/25; Drupal core alone is not affected
- ZoomEye: 436,370 Drupal installs, zero matches for the CVE
- Advisory urges logging file access and submitter-to-file links
Read next
Security