Why Patching CVE-2026-96369 Often Fails in Composer and Container Deployments
Vulnerability overview
CVE-2026-96369 appears in CERT-BUND advisory WID-SEC-2026-3554, published 23 September 2026 and rated high risk. The bulletin lists 36 identifiers, CVE-2026-96355 to CVE-2026-96398, and covers contributed Drupal projects rather than core. The structured record carries a CVSS v3.1 base score of 98 and a temporal score of 85 for the group.
The advisory names fixed releases for sixteen projects. Applying them is where deployments tend to go wrong.
Mechanism and exploitation conditions
CERT-BUND describes outcomes: arbitrary code execution, extended privileges, bypassed protections, data manipulation and disclosure, cross-site scripting. It identifies no vulnerable function and no parameter, and it does not map a single CVE to a single project.
Contributed modules are PHP executed in the Drupal request cycle under the web server account. Reachability depends on whether the module exposes a route accepting attacker-controlled input, and whether that route requires a session. The batch advisory does not settle those questions for CVE-2026-96369.
Impact
The impact list is a set of possible effects across the batch. Code execution against a module reaches the hosting account, since the web user can often read settings.php and write into public directories. Privilege escalation widens a constrained account. Data outcomes touch integrity and confidentiality. Cross-site scripting reaches authenticated sessions, administrative ones included.
Affected products and scope
Webform 6.2.12 and 6.3.1. Project Browser 2.0.3 and 2.1.5. Editoria11y Accessibility Checker 2.2.23 and 3.0.9. Webform REST 4.2.1. Cloud 7.0.1. Commerce Decoupled Checkout 1.8.0. Mermaid Diagram Field 1.0.9. CookieCuttr 2.0.3. REST & JSON API Authentication 3.2.0. Stop administrator login 1.6. Tawk.to Live chat application 3.0.4. AI CKEditor 1.4.3. Combined image style 1.0.7. CSS Usage Analyzer 1.0.2. Smart Content 3.2.1. Diba carousel slider 3.0.2.
Anything below the fixed release on the branch in use is affected. Drupal core is outside the advisory.
Exposure context
On 28 September 2026 ZoomEye returned 436,345 assets for app="Drupal". The companion query vul.cve="CVE-2026-96369" returned zero. The first describes the indexed Drupal fleet, the second describes index coverage for one identifier. Neither is a statement about a specific deployment.
Remediation and mitigations
Composer updates the lock file; it does not always update what the running container serves. Rebuild the image after the dependency change, and verify the module's .info.yml version inside the running container rather than in the build context. Where the image tag is pinned by digest, the pin has to move too.
Watch for the drift patterns. A module committed manually into modules/contrib is invisible to Composer. A vendor directory baked into an earlier layer survives a later composer update. A multi-stage build that copies from an older stage reproduces the old code.
After deploying, confirm the version from the application itself, then re-run the inventory that found the problem. If the same projects still appear at the old versions, the deployment did not land.
References
- CERT-BUND advisory WID-SEC-2026-3554, published 23 September 2026, high risk
- CERT-BUND structured advisory record, affected and fixed versions, CVSS v3.1 base 98, temporal 85
- ZoomEye search app="Drupal", executed 28 September 2026, exact count 436345












