Project: 
Date: 
2026-July-22
Vulnerability: 
Access bypass
Affected versions: 
<4.1.0
CVE IDs: 
CVE-2026-16644
Description: 

This module enables you to retrieve and submit webform submissions via REST endpoints.

The module doesn't sufficiently check the parent webform's permissions for creating, viewing and updating permissions.

This vulnerability is mitigated by the fact that an attacker must already have permissions to use the rest resource.

This advisory only affects already-unsupported versions 4.0.3 and earlier.

Solution: 

Install the latest version:

  • If you use the Webform Rest module for Drupal 8.x, upgrade to Webform Rest 4.1.0
  • Version 4.2.0 already has the fix included so no action needed if you use that version
Reported By: 
Coordinated By: