CRITICAL
9.1 CVE-2026-16644 Published 25 Aug 2026
Drupal Webform REST Forceful Browsing Vulnerability
Worried this affects one of your servers?
Drupal's Webform REST module is affected by an incorrect authorization vulnerability.
Webform REST versions from 0.0.0 to 4.1.0 are vulnerable, allowing forceful browsing.
Reference: CVE-2026-16644 on NVD
← Back to Security News