Critical severity9.1NVD Advisory· Published Aug 25, 2026· Updated Aug 28, 2026
CVE-2026-16644
CVE-2026-16644
Description
Incorrect Authorization vulnerability in Drupal Webform REST allows Forceful Browsing. This issue affects Webform REST versions: from 0.0.0 to 4.1.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Package: https://wordpress.org/plugins/drupal
- Range: 0.0.0 - 4.1.0
Patches
Vulnerability mechanics
References
1News mentions
1- Drupal Core: Five Security Advisories Disclosed in Single BatchVypr Intelligence · Jul 22, 2026