CVE-2026-96362: What the September 2026 Drupal Contributed Module Batch Means for Site Operators
Vulnerability overview
CERT-BUND advisory WID-SEC-2026-3554, published on 23 September 2026 and rated high risk, covers a batch of vulnerabilities in contributed Drupal projects. CVE-2026-96362 is one identifier inside that batch, which runs from CVE-2026-96355 to CVE-2026-96398 and contains 36 identifiers in total.
The advisory groups affected projects instead of isolating one module. Drupal core is not the subject. The exposure sits in add-on projects that individual site teams installed themselves, so the practical question is not whether Drupal is affected but which contributed code a given site actually runs.
Mechanism and exploitation conditions
The advisory describes the consequences in a single shared sentence: an attacker can execute arbitrary code, gain extended privileges, bypass security controls, manipulate and disclose data, and mount cross-site scripting attacks. It publishes no per-CVE root cause, no proof of concept and no list of the affected routes.
Contributed Drupal modules are PHP code that runs inside the Drupal request cycle, usually with the privileges of the web server user. A flaw in such a module becomes reachable when an anonymous or low-privilege visitor can reach the vulnerable controller, form or AJAX callback, and when attacker-controlled input reaches a sink the module failed to protect. Which of the 36 identifiers fall into which class is not stated in the advisory, so exploitation conditions remain per-project unknowns until each project advisory is read.
Impact
The impact list spans the range that matters for incident response. Code execution and privilege escalation decide whether a compromise stays inside content editing or extends to the hosting account. Drupal keeps database credentials in settings.php, so code running as the web user frequently reaches configuration and stored data beyond the affected module.
Data manipulation and disclosure matter for compliance and for trust in site records. Cross-site scripting matters for every authenticated session that touches an affected page, including administrative sessions.
Affected products and scope
The structured record lists 16 projects with 19 fixed versions, which means several projects shipped security releases on two supported branches at once.
- Webform: fixed in 6.2.12 and 6.3.1
- Webform REST: fixed in 4.2.1
- Cloud: fixed in 7.0.1
- Project Browser: fixed in 2.0.3 and 2.1.5
- Commerce Decoupled Checkout: fixed in 1.8.0
- Mermaid Diagram Field: fixed in 1.0.9
- CookieCuttr: fixed in 2.0.3
- REST & JSON API Authentication: fixed in 3.2.0
- Stop administrator login: fixed in 1.6
- Tawk.to Live chat application: fixed in 3.0.4
- Editoria11y Accessibility Checker: fixed in 2.2.23 and 3.0.9
- AI CKEditor: fixed in 1.4.3
- Combined image style: fixed in 1.0.7
- CSS Usage Analyzer: fixed in 1.0.2
- Smart Content: fixed in 3.2.1
- Diba carousel slider: fixed in 3.0.2 Drupal core is not listed as affected. The scope is contributed code, and the affected version is anything below the fixed release on the branch a site installed.
Exposure context
A ZoomEye query for the Drupal product fingerprint returned 436349 matching assets when it ran on 26 September 2026. A companion query for vul.cve="CVE-2026-96362" returned 0.
Those numbers answer different questions. The large figure counts Drupal deployments visible in the index and says nothing about which of them run a contributed module from this batch, let alone an unpatched version of one. The zero is an index result for this identifier and is not evidence that no deployment is affected.
Remediation and mitigations
Operators should start from an inventory of contributed projects. For each Drupal site, list the installed contributed modules and their versions, then compare that list against the 16 projects above.
Update to the fixed version on the branch the site uses. Read the project advisory before choosing a target version where two fixed releases exist. Where a module cannot be updated immediately, disable or remove it. Disabling a contributed module removes its routes from the request cycle, which is a stronger control than blocking paths at a proxy.
In practice, verification matters as much as the update itself. Drupal caches aggressively, and a container image or an unapplied database update can leave a correct-looking version string in front of vulnerable code. Confirm that the running code changed before closing the ticket.
References
- CERT-BUND advisory WID-SEC-2026-3554, Drupal extensions, published 23 September 2026, high risk: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3554
- CERT-BUND structured advisory record with affected and fixed versions for 16 contributed projects: https://wid.cert-bund.de/content/public/content/3f0df5d6-5291-41b3-92f2-0c016281c91f
- ZoomEye search app="Drupal", executed 26 September 2026, exact count 436349: https://www.zoomeye.ai/searchResult?q=YXBwPSJEcnVwYWwi












