CVE-2026-9082

Drupal core - Highly critical - SQL injection - SA-CORE-2026-004

Basic Information

CVE State
PUBLISHED
Reserved Date
May 20, 2026
Published Date
May 20, 2026
Last Updated
May 23, 2026
Vendor
Drupal
Product
Drupal core
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.1.10, from 11.2.0 before 11.2.12, from 11.3.0 before 11.3.10.
Tags
cisa nuclei_scanner

CVSS Scores

CVSS v3.1

9.8 - CRITICAL

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

SSVC Information

Exploitation
active
Automatable
Yes
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (2026-06-01 13:29:38 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CVE 2026-06-01 13:29:38 UTC

Scanner Integrations

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Detected by Nuclei