CVE-2026-96366

Broken Access
Affects
Webform
in
Drupal 7
No items found.
Versions
>=7.4.0 and <=7.4.27

Patch Available.

Exclamation circle icon
Patch Available

This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.

Overview

Drupal is an open-source content management system known for its flexibility, robust features, and strong community support. Organizations of all sizes use it to build and manage dynamic websites and web applications.

Webform is a Drupal module for building forms and surveys, such as contact forms, questionnaires and registrations, that stores submissions in the database and can email notifications when a form is submitted.

Webform's file upload component doesn't check that the file ID sent back with a submission belongs to the user who submitted it. A submitter can edit that ID to attach another user's file to their own submission, and can then get the file through their submission view or an email notification (the email vector requires the site to use an HTML-capable mail module such as Mime Mail).

Broken Access Control occurs when an application fails to properly enforce restrictions on what authenticated users are allowed to do, enabling attackers to access unauthorized functionality, data, or resources. It often stems from inadequate validation of user permissions, allowing someone to bypass intended security boundaries and perform actions beyond their assigned role.

Details

Module Info

Vulnerability Info

This medium-severity vulnerability is found in versions of the Drupal Webform module for Drupal 7 sites between versions 7.4.0 and 7.4.27 (inclusive).

Prior to the fix, the Webform file component (_webform_render_file() in components/file.inc) rendered a core managed_file element and accepted whatever file ID came back in the hidden submitted[<key>][fid] field, never checking that the submitting user had uploaded that file. Core's file_managed_file_value() skips its access check for public:// files and only rejects other users' temporary files, so any submitter, including an anonymous one, could replace the fid with that of another user's permanent public upload. _webform_submit_file() stored the fid as supplied and webform_file_usage_adjust() then attached the file to the attacker's submission, so the attacker could open it through their own submission view or, when the webform emails attachments, receive it through _webform_attachments_file() without ever knowing the file's URL.

A secondary weakness meant that deleting the attacker's submission, either through "delete own webform submissions" or when an administrator cleared results, ran _webform_delete_file(): it calls file_usage_delete($file, 'webform') with no submission ID, which removes every Webform usage record for the file, then file_delete(), which permanently deletes the victim's file if no other module uses it. Where file renaming is configured, file_move() could relocate the victim's file in the same way.

Addressing the Issue

Users of this module should apply one of the following mitigations:

  • If the risk is unacceptable, remove file components from webforms that untrusted or anonymous users can submit or disable those webforms until the fix can be deployed.
  • Revoke the "Access own webform submissions" and "Delete own webform submissions" permissions from untrusted roles, and turn off "Include files as attachments" on webform emails, so that a swapped-in file can't be viewed, received or deleted through an attacker's submission.
  • Set the "Upload destination" of file components to Private files (this needs a private file system path configured) and move existing uploads there. This protects webform uploads but not other public files on the site.
  • Audit webform submissions for file IDs that belong to files uploaded by other users (for example, where file_managed.uid differs from the submission's uid), and restore any deleted or moved files from backup.
  • Sign up for post-EOL security support—HeroDevs customers get immediate access to a patched version of this module.

Credits

Vulnerability Details
Severity
Level
CVSS Assessment
Low
>=0 <4
Medium
>=4 <6
High
>=6 <8
Critical
>=8 <10
Medium
ID
CVE-2026-96366
PROJECT Affected
Webform
Versions Affected
>=7.4.0 and <=7.4.27
NES Versions Affected
Published date
September 24, 2026
≈ Fix date
September 24, 2026
Category
Broken Access
Vex Document
Download VEXHow do I use it?
Sign up for the latest vulnerability alerts fixed in
NES for Drupal 7
Rss feed icon
Subscribe via RSS
or

By submitting the form I acknowledge receipt of our Privacy Policy.

Thanks for signing up for our Newsletter! We look forward to connecting with you.
Oops! Something went wrong while submitting the form.