Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

To assess a Drupal site for CVE-2026-96364, check the installed contributed Webform version and the affected form’s configuration. Drupal’s advisory describes a possible anti-spam bypass on Ajax-enabled forms when Webform Share is enabled, sharing is enabled for the form, and compatible Form API anti-spam protection is in use. The advisory does not provide a CVE-specific remote scan signature, so an external scan alone cannot confirm that a site is safe.

What CVE-2026-96364 affects

Drupal’s SA-CONTRIB-2026-171, published September 23, 2026, classifies CVE-2026-96364 as a moderately critical access bypass in the contributed webform project, with a Drupal risk rating of 14/25. That rating is Drupal’s advisory score, not a CVSS score or a measure of how many sites are exposed.

The issue is not a Drupal core vulnerability. Drupal says that under certain circumstances submissions to an Ajax-enabled Webform using Webform Share can bypass anti-spam protections. The OSV record corroborates the affected version ranges and fixes.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Check the installed Webform version

Start with an internal inventory of every relevant site and environment, including production, staging, and other deployed copies. Record the Webform branch and exact installed version; a branch distinction matters because the affected ranges and fixes are branch-specific.

Webform version Advisory status Fixed release for that branch
Earlier than 6.2.12 in the 6.2.x branch Affected range 6.2.12
6.3.0 through versions earlier than 6.3.1 Affected range 6.3.1
Outside the affected ranges listed above Not identified as affected by this advisory Not applicable to the listed ranges

Drupal names 6.2.12 for the 6.2.x branch and 6.3.1 for the 6.3.x branch as fixed releases. A version outside the listed ranges is not identified as affected by this advisory; that does not establish that the site has no other security issues.

Determine whether the affected configuration applies

For a site running an affected version, assess the specific forms rather than treating module presence alone as proof of exposure. Drupal’s advisory describes a combination of conditions:

Rank #2
BookFactory Security Pass Down Log Book, Wire-O, 100 Pages
  • Made in USA - Proudly produced in Ohio by a Veteran-owned business
  • Comprehensive Coverage: This BookFactory log book includes essential fields such as post/shift, time of change, date, weather conditions, and a designated space for detailed notes. This ensures that all relevant information is captured and easily accessible.
  • Sturdy Cover: The trans-lux cover protects the log book from wear and tear, ensuring its longevity and maintaining the integrity of your recorded data.
  • Essential Security Tool: This log book is an indispensable tool for any organization that values security and accountability. It helps to prevent misunderstandings, improve communication, and ensure a smooth transition between shifts.
  • Wire-O with Trans-lux cover, 100 Pages, Dimensions 8.5" x 11" - (Security-Pass-Down) Reorder SKU: LOG-100-7CW-PP(Security-Pass-Down)
  • Webform Share is enabled.
  • Sharing is enabled for the particular webform.
  • The form is Ajax-enabled.
  • The form uses compatible Form API-based anti-spam protection, such as Honeypot or Antibot.

Review the relevant module and form settings in the site’s own configuration. If the prerequisites do not all apply, the advisory’s described scenario is not established for that form. If they do apply, prioritize updating the affected Webform branch.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Remediate and verify the deployment

  1. Upgrade Webform 6.2.x to 6.2.12 or Webform 6.3.x to 6.3.1, as appropriate to the installed branch.
  2. After deployment, verify the installed package and version on each affected site and environment.
  3. Recheck the relevant Webform Share, form-sharing, Ajax, and anti-spam configuration, and retain the inventory and deployment record as evidence of the check.

This is an operational version-and-configuration verification based on Drupal’s advisory conditions and fix guidance. It is not a published exploit-reproduction test.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What a remote scan can and cannot establish

Drupal’s advisory lists affected versions, configuration prerequisites, impact, and fixes, but does not document a request signature, payload, log query, or official remote probe for determining whether a live site is exploitable. Do not interpret a clean result from a generic scanner—or the absence of suspicious requests—as proof that the affected configuration is absent.

This is a limit of what the cited official advisory publishes; it does not establish that no third-party detection method exists. The Drupal contributed-project advisory catalog also records the CVE and advisory association.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.