· via dev.to (home feed)
Drupal patches CVE-2026-96363 XSS in Webform's Entity Print submodule
A moderately critical XSS flaw in Drupal's Webform Entity Print submodule is fixed in Webform 6.2.12 and 6.3.1; only sites with the submodule enabled and specific authoring permissions are exposed.

What happened
Drupal security advisory SA-CONTRIB-2026-161, published on 23 September 2026, covers CVE-2026-96363 in the Webform contributed module. According to a dev.to analysis of the advisory, the vulnerable code lives in Webform Entity Print, a submodule bundled inside the Webform project, and the issue is classified as cross-site scripting with a rating of moderately critical — 10 out of 25 on Drupal's advisory scale. Drupal core is not named as affected.
That distinction is practical rather than pedantic. Core vulnerabilities tend to trigger site-wide emergency processes, while contributed-module issues occupy a different operational compartment: a site may never have installed the project at all, and even installed projects can ship optional submodules that are never switched on.
Who is actually exposed
The dev.to post explains that the submodule fails to properly restrict access to its print templates. A user who holds both the "create webform" and "edit own webform" permissions can carry out cross-site scripting through the submodule's settings. Both the enabled submodule and that permission pair are required for exploitation.
Webform Entity Print ships disabled by default, so a site can run an affected Webform release for a long time without the vulnerable code path ever being reachable. As the post puts it, saying "Drupal is vulnerable to CVE-2026-96363" overstates the case; the accurate statement is that sites running Webform Entity Print on an affected branch, with a role granting both authoring permissions, are exposed. The first framing puts every Drupal owner in scope; the second narrows the population to a specific configuration.
A batch advisory blurs the picture
Part of the confusion comes from coordinated releases. CERT-BUND notice WID-SEC-2026-3554 gathers 36 CVE identifiers across 16 contributed Drupal projects into a single high-risk notice, with a batch-level CVSS v3.1 base score of 9.8 and a temporal score of 8.5 as reported by the dev.to post. Those numbers describe the roll-up, not this individual flaw — within the same release, Drupal advisories cover everything from cross-site scripting and access bypass to denial of service, cross-site request forgery and remote code execution. The dev.to author's guidance is to read the classification from the project-specific advisory and the breadth from the batch notice, not the other way around.
What internet scans show
A ZoomEye query for Drupal assets returned 436,397 matches on 27 September 2026, while a query tagged to CVE-2026-96363 returned zero. Neither figure settles the question of exposure: the large count cannot separate sites that enabled the submodule from those that did not, and the zero is an index result captured at one point in time rather than evidence that no deployments are vulnerable.
How to fix it
The remediation is straightforward. Sites on the 6.2.x branch should update Webform to 6.2.12, and sites on 6.3.x should move to 6.3.1. Where Webform Entity Print is not needed, disabling it removes the affected code path even before the update has been applied. Administrators are also advised to review which roles hold the two authoring permissions, and to confirm the installed version directly after updating instead of relying on the update queue's reported status.
Why it matters
Vulnerabilities in contributed modules are routinely flattened into "Drupal has a critical flaw" headlines, prompting emergency responses far broader than necessary — or, just as damaging, the assumption that a moderate rating means no action at all. The correct triage here is a three-question check: is Webform installed, is Entity Print enabled, and does any role hold both authoring permissions? Teams answering yes to all three have a real but routine patch, with disabling the submodule available as an immediate mitigation. The case also highlights a blind spot in asset inventories: submodule-level flaws ship with popular projects but do not inherit their default exposure, so tracking only top-level modules can leave gaps in what a security team believes it is running.
- #drupal
- #security
- #cve
- #xss
- #webform