Why CVE-2026-96363 Is the Submodule Problem, Not a Drupal Core Problem

Why CVE-2026-96363 Is the Submodule Problem, Not a Drupal Core Problem

为什么 CVE-2026-96363 是子模块问题,而非 Drupal 核心问题

The distinction that matters. Drupal security advisory SA-CONTRIB-2026-161, published 23 September 2026, covers CVE-2026-96363 and the affected project is Webform, a contributed module. The affected code path is Webform Entity Print, a submodule that ships inside the Webform project. Drupal core is not named as affected. 这是一个至关重要的区别。2026 年 9 月 23 日发布的 Drupal 安全公告 SA-CONTRIB-2026-161 涵盖了 CVE-2026-96363,受影响的项目是贡献模块 Webform。受影响的代码路径是 Webform Entity Print,这是一个包含在 Webform 项目内部的子模块。Drupal 核心并未被列为受影响对象。

That distinction is practical. Core vulnerabilities trigger site-wide emergency processes. Contributed module issues live in a different operational compartment, where a site may or may not have installed the project at all, and where the submodule may or may not be enabled. 这种区别具有实际意义。核心漏洞会触发全站范围的紧急处理流程。而贡献模块的问题则处于不同的操作范畴,因为站点可能根本没有安装该项目,或者即使安装了,该子模块也可能并未启用。

How the submodule is different again. Webform Entity Print is one step further down. It is bundled with Webform but disabled by default, which means a site can run an affected Webform version for months without ever exposing the code path the advisory describes. The advisory is specific about the consequence of that packaging. The submodule does not sufficiently limit access to its print templates, and a user holding create webform and edit own webform can exploit cross-site scripting through the submodule settings. Both the submodule and the permission pair are required. 子模块的情况则更为特殊。Webform Entity Print 更深一层。它虽然与 Webform 捆绑在一起,但默认是禁用的,这意味着一个站点即使运行着受影响的 Webform 版本,也可能在数月内从未暴露公告中所述的代码路径。公告明确指出了这种打包方式带来的后果:该子模块未能充分限制对其打印模板的访问,拥有“创建 Webform”和“编辑自己的 Webform”权限的用户可以通过子模块设置利用跨站脚本(XSS)漏洞。利用该漏洞必须同时满足子模块已启用和具备上述权限对这两个条件。

What an accurate risk statement looks like. A statement that says Drupal is vulnerable to CVE-2026-96363 overstates the case. A statement that says Drupal sites running Webform Entity Print on an affected Webform branch, with a role granting both authoring permissions, are exposed is accurate and actionable. The difference changes who gets woken up at night. Under the first framing, every Drupal owner in an organisation is in scope. Under the second, the population is sites that installed Webform, enabled the submodule, and granted the permissions. 准确的风险声明应该是怎样的?声称“Drupal 易受 CVE-2026-96363 攻击”夸大了事实。而声称“在受影响的 Webform 分支上运行 Webform Entity Print,且拥有授予上述两种创作权限角色的 Drupal 站点面临风险”则是准确且可操作的。这种区别决定了谁需要在深夜被叫醒处理问题:按照第一种说法,组织内所有的 Drupal 拥有者都在受影响范围内;而按照第二种说法,受影响的仅限于那些安装了 Webform、启用了该子模块并授予了相应权限的站点。

Why coordinated releases blur this. WID-SEC-2026-3554 collects 36 CVE identifiers across 16 contributed projects in one high-risk notice, with a batch-level CVSS v3.1 base score of 98 and temporal score of 85. Those figures describe a roll-up. Within the same release, Drupal advisories classify individual identifiers as cross-site scripting, access bypass, denial of service, cross-site request forgery and remote code execution. SA-CONTRIB-2026-161 classifies this one as cross-site scripting, moderately critical, 10 out of 25. Reading the classification from the project notice and the breadth from the batch notice is the accurate combination. 为什么协调发布会模糊这一点?WID-SEC-2026-3554 在一份高风险通知中汇总了 16 个贡献项目中的 36 个 CVE 标识符,其批次级 CVSS v3.1 基础评分为 98,时间评分为 85。这些数字描述的是一个汇总结果。在同一次发布中,Drupal 公告将各个标识符分类为跨站脚本、访问绕过、拒绝服务、跨站请求伪造和远程代码执行。SA-CONTRIB-2026-161 将此漏洞归类为跨站脚本,中等严重程度,评分为 10/25。结合项目公告中的分类和批次通知中的广度信息,才是准确的解读方式。

Exposure context. A ZoomEye query for app=“Drupal” returned 436397 matching assets on 27 September 2026, and a query for vul.cve=“CVE-2026-96363” returned zero. The large number counts Drupal assets visible in the index and cannot separate sites that enabled the submodule from those that did not. The zero is an index result at a point in time, not a clean bill of health. 暴露情况背景。2026 年 9 月 27 日,针对 app=“Drupal” 的 ZoomEye 查询返回了 436,397 个匹配资产,而针对 vul.cve=“CVE-2026-96363” 的查询结果为零。庞大的数字统计的是索引中可见的 Drupal 资产,无法区分哪些站点启用了该子模块,哪些没有。零的结果仅代表该时间点的索引状态,并不代表系统是完全健康的。

Remediation. Update Webform to 6.2.12 on the 6.2.x branch or 6.3.1 on the 6.3.x branch. If Webform Entity Print is not needed, disabling it removes the affected code path whether or not the update has been applied yet. Review which roles hold create webform and edit own webform, and confirm the installed version after updating rather than trusting the update queue. 修复建议。将 Webform 更新至 6.2.x 分支的 6.2.12 版本或 6.3.x 分支的 6.3.1 版本。如果不需要 Webform Entity Print,禁用它即可移除受影响的代码路径,无论是否已经应用了更新。请检查哪些角色拥有“创建 Webform”和“编辑自己的 Webform”权限,并在更新后确认已安装的版本,而不是盲目信任更新队列。

References:

  • Drupal security advisory SA-CONTRIB-2026-161, Webform, cross-site scripting, affected versions <6.2.12 and >=6.3.0 <6.3.1
  • CERT-BUND advisory WID-SEC-2026-3554, Drupal extensions, multiple vulnerabilities, high risk
  • ZoomEye search app=“Drupal”, 27 September 2026, exact count 436397
  • ZoomEye search vul.cve=“CVE-2026-96363”, 27 September 2026, exact count 0 参考资料:
  • Drupal 安全公告 SA-CONTRIB-2026-161,Webform,跨站脚本,受影响版本 <6.2.12 及 >=6.3.0 <6.3.1
  • CERT-BUND 公告 WID-SEC-2026-3554,Drupal 扩展,多个漏洞,高风险
  • ZoomEye 搜索 app=“Drupal”,2026 年 9 月 27 日,精确计数 436397
  • ZoomEye 搜索 vul.cve=“CVE-2026-96363”,2026 年 9 月 27 日,精确计数 0