
Palak Agrawal
Published on September 28, 2026
10 min read
Share on:
A contact form may look like one of the simplest parts of a website. Behind that form, however, there can be software handling user input, uploaded files, submitted data, emails, and other website functions.
That is why a security issue in a form module can have consequences beyond the form itself.
On 23 September 2026, the Drupal Security Team released a series of security updates for the Webform module, one of the most widely used contributed modules for building forms in Drupal. The release fixes several security issues, including cross-site scripting, access bypass, server-side request forgery, and a critical remote code execution vulnerability.
The critical issue does not affect every Webform installation. It requires a specific configuration involving custom multiple-value formats and submission-value tokens. This article explains what Webform does, what security issues were found, what was included in the 23 September release, and what you should do next.

Webform is a contributed Drupal module that allows site builders to create forms, collect submissions, and manage the information users provide.
A basic website may use Webform for a contact or feedback form. Larger organisations may use it for more complex processes such as:
The module also supports email handlers, integrations, custom formatting, and other features that allow organisations to build forms around specific business processes.
That means Webform can sit between a website visitor and information stored on the site. A submission may contain a name and email address, but it could also contain application details, customer information, uploaded documents, or other personal data.
This makes the security of the module important, especially on websites that use advanced Webform features.
The Webform project currently provides supported releases for Drupal 10 and Drupal 11, including the security releases issued on 23 September.
On 23 September, the Drupal Security Team published a series of Webform security advisories. The problems covered different parts of the module and did not all require the same configuration or permissions.
The main categories were:
Several issues could allow unsafe content to be interpreted as script in a user's browser under specific conditions. Some of these issues involved uploaded files or the way Webform content was rendered.
Several vulnerabilities involved Webform access controls. Under certain conditions, users could reach data or functionality that should have been restricted.
An issue in the Webform Submission Export/Import functionality could allow a user with certain permissions to access the remote URL import path and cause requests to be made from the server.
One issue could allow a malicious request to consume significant server resources when a Webform was displayed to anonymous visitors under a specific configuration.
This was the most serious vulnerability in the release.
The critical vulnerability is tracked as SA-CONTRIB-2026-175 and CVE-2026-96355. Drupal rated it 18 out of 25, with the exploit status listed as theoretical at the time of disclosure.
The problem is related to how Webform handles token replacement in certain format templates.
For the vulnerability to apply, a Webform must use a custom multiple-value item format that includes submission-value tokens. In that situation, an attacker could submit data that is later evaluated as template code when the submission is rendered.
Depending on the site's configuration and enabled modules, the issue could result in:
This does not mean every website using Webform is exposed to the critical vulnerability. The affected configuration is specific. However, the number of other security issues included in the same release means site owners should still review and apply the update.

The 23 September update was more than a fix for the critical remote code execution issue. The Webform project released new versions containing a coordinated set of 22 security fixes and one additional hardening change.
The release also strengthened several parts of Webform, including:
The additional hardening change also warns site builders when an autocomplete element may expose values collected from existing submissions. This gives administrators a chance to review whether that setup is appropriate for the users who can access the form.
Not every Webform installation is exposed to every issue. Some vulnerabilities depend on particular features, configurations, integrations, or user permissions.
That distinction matters because a site may not use the feature connected to one advisory but still be affected by another.
The Drupal Security Team gave site owners advance notice before the release.
On 21 September 2026, it announced that a widely used contributed module would receive a significant number of security fixes on 23 September. The announcement did not name Webform at first.
The release was scheduled for 17:00 to 21:00 UTC on 23 September. The Webform advisories were then published during that window. Drupal said the advisories could be published in batches because of the number of issues involved.
The Webform advisories covered numbers from SA-CONTRIB-2026-154 through SA-CONTRIB-2026-175. Two numbers, 156 and 157, were accidentally skipped and do not represent missing advisories.
The wider release also included advisories for other contributed projects. Drupal core was not affected.
The Drupal Security Team also confirmed before the release that these updates would not be covered by Drupal Steward. Organisations relying on Drupal Steward therefore still needed to apply the Webform updates themselves.
The update depends on which Webform branch your site is running.
Current Webform branch | Update to |
Webform 6.2.x | 6.2.12 |
Webform 6.3.x | 6.3.1 |
Webform 6.2.12 is the release for Drupal 10, while Webform 6.3.1 is the release for Drupal 11. Both releases contain the same coordinated set of 22 security fixes and one additional hardening change.
If you manage a Drupal site through Composer, the Webform project provides the corresponding Composer update paths for these releases.
Before applying the update to production, test it in your normal development or staging workflow. Pay particular attention to forms that use file uploads, custom formatting, submission exports, remote handlers or integrations.
Updating Webform should be the first step, but it should not necessarily be the last. After the update, review the Webform features your site actually uses.

Look at whether your site uses features such as Submission Export/Import, Webform Share, Entity Print or other integrations covered by the release.
Several of the advisories depend on what users are allowed to do. Check who can create or edit webforms, view submissions, manage handlers, export data or configure remote operations.
If you use Webform Submission Export/Import with remote URLs, configure the trusted hosts recommended by Drupal.
If your forms use custom multiple-value formats or submission-value tokens, review those configurations carefully because they are relevant to the critical RCE vulnerability.
Submit test entries and check confirmation messages, email handlers, file uploads, submission views and any integrations connected to the form.
This gives you a much clearer picture of whether the update has affected anything your site depends on.
The Webform release is a good example of why security updates need to be part of regular Drupal maintenance rather than something you handle only when a critical vulnerability makes the news.
Here are five important reasons as to why these security updates are important.
Once a security issue is disclosed, the details are public. Applying the available fix reduces the amount of time your site remains exposed to a known problem.
Regular updates are easier to manage than a large catch-up exercise. Keeping your modules reasonably current means your team has fewer changes to review and test when a security release arrives.
Regulations such as GDPR expect organisations to take appropriate measures to protect personal information. Keeping software updated is one part of maintaining that security process.
Applying and testing an update takes time, but recovering from a security incident can require investigation, remediation, communication with affected users, and additional technical work.
When a site is already maintained regularly, a critical security update is usually a smaller task. Teams are less likely to discover that several other outdated components need attention before the security fix can be applied.
Regular updates do not eliminate security risks, but they remove known vulnerabilities before they become a bigger problem.
The 23 September 2026 Webform security release addresses a broad set of security issues, including a critical remote code execution vulnerability linked to specific Webform configurations. Site owners using Webform 6.2.x should upgrade to 6.2.12, while those on 6.3.x should move to 6.3.1.
Applying the update is one part of keeping a Drupal website secure. Site owners should also review permissions, configurations, integrations, and other components that could introduce security risks over time. Regular website audits can help teams find these issues before they turn into larger security problems.
DrupalFit helps Drupal teams audit their websites for security, accessibility, performance, privacy, and compliance issues. By bringing these checks into one dashboard, teams can get a broader view of their website's security posture and identify areas that need attention.
Sites running the 6.2.x branch should update to 6.2.12, while sites running the 6.3.x branch should update to 6.3.1. The critical vulnerability is tracked as CVE-2026-96355.
No. The Drupal Security Team classified the exploit status as theoretical, meaning there was no known public exploit at the time of disclosure. That can change once vulnerability details become public, which is why applying the available fix promptly is still important.
Drupal core was not affected. The 23 September security release covered vulnerabilities across contributed Drupal projects, including Webform.
Yes. The Submission Export/Import issue is separate from the critical remote code execution vulnerability. Not using that feature removes your exposure to that specific SSRF issue, but other Webform vulnerabilities may still apply to your site.
No. The Drupal Security Team stated that this release was not covered by Drupal Steward. Sites relying on the programme therefore needed to apply the Webform update themselves.