CVE-2026-9082: Highly Critical Drupal Core SQL Injection Flaw Threatens PostgreSQL Sites
ID: 93598c11-a4cc-568d-8cfa-7eed7316a800
STIX ID: report--93598c11-a4cc-568d-8cfa-7eed7316a800
Feed Name: SOC Prime Blog
Drupal disclosed CVE-2026-9082, a PostgreSQL-specific SQL injection in Drupal Core's database abstraction API exploitable by anonymous users; successful exploitation can disclose sensitive data and, depending on configuration, lead to privilege escalation or remote code execution. Drupal published fixed releases for affected branches (e.g., 11.3.10, 10.6.9, etc.) and advises immediate patching, inventorying sites for PostgreSQL, and prioritizing public-facing installations while no public PoC or wide exploit telemetry has been published.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
