Webform REST - Moderately critical - Access bypass - SA-CONTRIB-2026-087

Project: Webform RESTDate: 2026-July-22Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:DefaultVulnerability: Access bypassAffected versions: <4.0.3CVE IDs: CVE-2026-16644Description: This module enables you to retrieve and submit webform submissions via REST endpoints.
The module doesn't sufficiently check the parent webform's permissions for creating, viewing and updating permissions.
This vulnerability is mitigated by the fact that an attacker must already have permissions to use the rest resource.
This advisory only affects already-unsupported versions 4.0.3 and earlier.Solution: Install the latest version:

  • If you use the Webform Rest module for Drupal 8.x, upgrade to Webform Rest 4.1.0
  • Version 4.2.0 already has the fix included so no action needed if you use that version

Reported By: 

Fixed By: 

Coordinated By: 

Path to article https://www.drupal.org/sa-contrib-2026-087