logo

Drupal core vulnerability CVE-2026-9082: Find impacted assets

ID: d4635579-94f6-5c91-9414-adae4875cb15

STIX ID: report--d4635579-94f6-5c91-9414-adae4875cb15

Feed Name: runZero Blog

Threat Score
90/100

Date Published: 2026-05-22

Date Updated: 2026-05-23

Author: Matthew Kienow

...
...

Drupal core is affected by a critical SQL injection vulnerability (CVE-2026-9082, CVSS 9.8) in the database abstraction API that allows remote, unauthenticated attackers to send crafted requests resulting in arbitrary SQL execution on sites configured to use PostgreSQL; successful exploitation can lead to information disclosure, privilege escalation, RCE, and other attacks, and there is evidence of active exploitation in the wild. Multiple Drupal versions are listed as affected, and the advisory provides version-specific patches and upgrade guidance to mitigate the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.