Detection and verification limits for CVE-2026-96364 on a live Drupal estate
Vulnerability overview
CVE-2026-96364 is listed in CERT-BUND WID-SEC-2026-3554, published 23 September 2026, covering 36 identifiers and 16 contributed Drupal projects. The advisory is rated high, flagged remotely exploitable, and carries CVSS version 3.1 base score 98 with temporal score 85. Patch availability is confirmed by the advisory's patch field.
Detection questions
The batch record does not publish a trigger for CVE-2026-96364, which constrains detection. A network signature needs a request pattern, and a file integrity signature needs a known artifact. Neither is available from the record, and the association between the identifier and a specific project is not published there either. The per-project advisory is the place to look for class and version information.
Verification approach
Verification therefore has to be version based and inventory based. The reliable signal is the installed project version read from the site's own status report or Composer lock, checked against the range table for the branch in use. Chasing exploit indicators without a published pattern produces alerts that cannot be triaged.
Impact
The practical impact of the detection gap is a bias toward assurance by inventory. An organisation that can answer, per site, which of the 16 projects are installed and at which version has covered the question the batch record can answer. An organisation relying on remote scanning alone has not, because a module behind authentication is invisible to an external scanner.
Affected products and scope
Affected projects: Webform, Cloud, Project Browser, Commerce Decoupled Checkout, Mermaid Diagram Field, CookieCuttr, REST and JSON API Authentication, Stop administrator login, Tawk.to live chat, Editoria11y Accessibility Checker, Webform REST, AI CKEditor, Combined image style, CSS Usage Analyzer, Smart Content and Diba carousel slider. Fixed releases: Webform 6.2.12 and 6.3.1, Cloud 7.0.1, Project Browser 2.0.3 and 2.1.5, Commerce Decoupled Checkout 1.8.0, Mermaid Diagram Field 1.0.9, CookieCuttr 2.0.3, REST and JSON API Authentication 3.2.0, Stop administrator login 1.6, Tawk.to live chat 3.0.4, Editoria11y Accessibility Checker 2.2.23 and 3.0.9, Webform REST 4.2.1, AI CKEditor 1.4.3, Combined image style 1.0.7, CSS Usage Analyzer 1.0.2, Smart Content 3.2.1 and Diba carousel slider 3.0.2. Core is outside the advisory. Two projects appear on two branches each, so a single-branch inventory under-reports the estate.
Exposure context
ZoomEye returned 436388 assets for app="Drupal" on 27 September 2026 and zero for vul.cve="CVE-2026-96364". A zero here reflects index coverage for one string and is not evidence that no installation is affected.
Remediation and mitigations
Build the version check first, because it doubles as remediation input: export installed projects and versions, diff against the range table, and mark each row affected, fixed or absent. Update affected rows to the fixed release for their branch. Where update is not possible, disable the module or restrict its routes. Then re-verify from the status report, and keep the export as the baseline for the next batch. Treat any indicator-based detection as supplementary until a mechanism is published.
References
- CERT-BUND advisory WID-SEC-2026-3554, Drupal extensions, 23 September 2026
- Drupal Security Advisories sa-contrib-2026-154 through sa-contrib-2026-191, 23 September 2026
- Drupal security advisories index
- ZoomEye search for app="Drupal"
Top comments (0)