deniz.in

Markets

Weather

Loading weather

· via dev.to (home feed)

36 high-risk Drupal module CVEs expose the blind spot in version-based scanning

CERT-BUND rates a 36-CVE batch spanning 16 contributed Drupal projects as high risk, and internet-wide scanners largely cannot see which sites run the affected modules.

36 high-risk Drupal module CVEs expose the blind spot in version-based scanning

What the advisory covers

On 23 September 2026, CERT-BUND published advisory WID-SEC-2026-3554, a batch of vulnerabilities in contributed Drupal projects rated high risk. According to a dev.to analysis of the advisory, the identifiers run from CVE-2026-96355 through CVE-2026-96398 — 36 CVEs in total, with CVE-2026-96362 among them. Drupal core is not on the list; every affected project is third-party contributed code installed at a site owner's discretion.

The advisory states the consequences for the batch as a whole: arbitrary code execution, extended privileges, bypassed security controls, manipulated and disclosed data, and cross-site scripting. It gives no per-CVE root cause, proof of concept, or route list. Contributed modules are PHP executing inside Drupal's request cycle, typically with web server privileges, so whether any single flaw is exploitable depends on whether an anonymous or low-privilege visitor can reach the affected controller, form, or AJAX callback and push attacker-controlled input into an unprotected sink.

Exposure numbers that mislead

The dev.to piece contrasts two ZoomEye queries run on 26 September 2026. A search for app="Drupal" returned 436,349 assets; a search for vul.cve="CVE-2026-96362" returned zero. Both figures describe what an internet-wide index can observe from the outside, not what runs inside any given site. The first says nothing about which deployments carry a module from this batch — externally visible Drupal installations rarely expose their full internal module inventory. The second reflects the index's coverage of one identifier and is not proof that no site is affected.

The case for treating the batch seriously is structural rather than CVE-specific. Code execution or privilege escalation in a module can move an attacker past that module into the hosting account, where settings.php stores database credentials that code running as the web user can typically read. Cross-site scripting reaches authenticated sessions, administrators included, and data manipulation or disclosure carries compliance consequences.

Sixteen projects, nineteen fixed versions

CERT-BUND's structured record names 16 projects with 19 fixed versions. Any install below the fixed release on its branch remains affected.

  • Webform: 6.2.12 and 6.3.1
  • Webform REST: 4.2.1
  • Cloud: 7.0.1
  • Project Browser: 2.0.3 and 2.1.5
  • Commerce Decoupled Checkout: 1.8.0
  • Mermaid Diagram Field: 1.0.9
  • CookieCuttr: 2.0.3
  • REST & JSON API Authentication: 3.2.0
  • Stop administrator login: 1.6
  • Tawk.to Live chat application: 3.0.4
  • Editoria11y Accessibility Checker: 2.2.23 and 3.0.9
  • AI CKEditor: 1.4.3
  • Combined image style: 1.0.7
  • CSS Usage Analyzer: 1.0.2
  • Smart Content: 3.2.1
  • Diba carousel slider: 3.0.2

How operators should respond

The dev.to analysis recommends deciding exposure from an internal inventory rather than external scanning: compare installed contributed modules against the 16 named projects and update to the fixed release for the branch in use, checking the individual project advisory where two fixed releases exist. When an update cannot be scheduled promptly, disabling a module takes its routes out of the request cycle.

Verification should target the running code, not reported version strings. Drupal's caching layers and container reuse can leave a patched-looking version string over unpatched files, in which case a scanner reading that string would call the site clean when it is not.

Why it matters

The batch shows where the standard scanning model breaks down for CMS ecosystems. Version fingerprinting works when a CVE names a product whose version is externally visible; it fails when the vulnerable component is an optional module whose presence is known only to the site operator. The ZoomEye contrast — 436,349 Drupal deployments visible, zero flagged for the headline CVE — is not evidence that sites are safe, but evidence of what scanners cannot see. Site owners hold the information the tooling lacks: which modules are installed, which branch they track, and what code is actually executing. Until remediation workflows treat internal inventory as the primary signal, advisories like WID-SEC-2026-3554 will be actionable only to operators who already know exactly what they run.

  • #drupal
  • #security
  • #cve
  • #vulnerabilities
  • #cms

Related posts