logo

Drupal Database API Flaw (CVE-2026-9082) Exposes PostgreSQL Sites to Unauthenticated SQLi

ID: f2fcdc58-d7be-5ed9-8fd4-f60ae5f473b6

STIX ID: report--f2fcdc58-d7be-5ed9-8fd4-f60ae5f473b6

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-05-21

Date Updated: 2026-05-21

Author: Ddos

...
...

The Drupal Security Team released an urgent advisory (SA-CORE-2026-004, CVE-2026-9082) for a critical arbitrary SQL injection in Drupal’s database abstraction API affecting sites using PostgreSQL. The flaw permits remote, unauthenticated attackers to bypass sanitization and execute raw SQL, enabling data disclosure, privilege escalation, and in some PostgreSQL configurations, remote code execution; administrators are urged to apply the provided core updates immediately and to update upstream dependencies (Symfony/Twig) and audit template-editing permissions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.