Project:
Project machine name:
webform_submissions_deleteDate:
2026-September-02
Vulnerability:
Access bypass
Affected versions:
<1.2.0
CVE IDs:
CVE-2026-84921
Description:
This module enables you to delete Webform submissions in bulk using a specified date range.
The module doesn't sufficiently restrict access to the delete form.
A separate PHP fatal error issue may prevent exploitation in practice on Drupal 10+.
Solution:
Install the latest version:
- If you use the Webform Submissions Delete module, upgrade to Webform Submissions Delete 8.x-1.2
Reported By:
Fixed By:
Coordinated By:
- Swan Kalata (akalata) of the Drupal Security Team
- Damien McKenna (damienmckenna) of the Drupal Security Team
- Dan Smith (galooph) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Pierre Rudloff (prudloff) of the Drupal Security Team