logo

CVE-2026-9082: Highly Critical SQL Injection Vulnerability in Drupal Core (SA-CORE-2026-004)

ID: 3da5cd0f-6f48-5d9e-9ff5-18b5943deb06

STIX ID: report--3da5cd0f-6f48-5d9e-9ff5-18b5943deb06

Feed Name: Tenable Blog

Threat Score
78/100

Date Published: 2026-05-21

Date Updated: 2026-06-04

Author: Satnam Narang

...
...

**Executive Summary:** A highly critical SQL injection (CVE-2026-9082) in Drupal core's database abstraction API affects sites using PostgreSQL; unauthenticated attackers can exploit crafted requests to disclose, modify, or delete data, and proof-of-concept and patch diffs were publicly shared the day of disclosure with observed exploitation attempts reported shortly after, prompting coordinated fixes across multiple Drupal releases and inclusion in CISA's KEV.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.