SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-16644

CRITICAL · CVSS 9.1 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Drupal Webform REST versions 0.0.0 to 4.1.0 are susceptible to an Incorrect Authorization vulnerability that enables forceful browsing, potentially allowing unauthorized users to access restricted resources. Organizations using these versions should prioritize remediation to prevent unauthorized data exposure and ensure compliance with security best practices. Immediate attention is recommended for those managing web applications built on Drupal that utilize the Webform REST module.

CVE
CVE-2026-16644
Severity
CRITICAL
CVSS
9.1
EPSS
0.31%

Original NVD Description

Incorrect Authorization vulnerability in Drupal Webform REST allows Forceful Browsing. This issue affects Webform REST versions: from 0.0.0 to 4.1.0.