logo

CVE-2026-9082: Critical Drupal SQL Injection Vulnerability Affects PostgreSQL Deployments

ID: 9a342ac0-f651-5712-a042-b5960ec8e320

STIX ID: report--9a342ac0-f651-5712-a042-b5960ec8e320

Feed Name: Security Boulevard

Threat Score
90/100

Date Published: 2026-05-26

Date Updated: 2026-05-26

Author: Deepak Kumar Choudhary

...
...

Executive summary: CVE-2026-9082 is a highly critical, unauthenticated SQL injection in Drupal's PostgreSQL EntityQuery condition handler that has been publicly disclosed, patched across supported branches, added to CISA's Known Exploited Vulnerabilities catalog, and observed in active exploitation; organizations running PostgreSQL-backed Drupal sites should apply the provided fixes immediately, audit permissions and query behavior, and employ WAF protections while remediating.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.