Vulnerability detail
Enriched intelligence for a single CVE
Critical
CVE-2026-9082
PUBLISHEDDrupal core - Highly critical - SQL injection - SA-CORE-2026-004
1 day faster than CISA KEV
- Vendor
- Drupal
- Product
- Drupal core
- Published
- May 20, 2026
- EPSS
- 10.4% · 93% pctl
Automate this intelligence with the Pro API
Everything on this page — CVSS, EPSS, exploit status, PoCs, scanner integrations, mentions, tags, and immediate honeypot data — is available programmatically for VM, SOC, and CTI workflows.
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.1.10, from 11.2.0 before 11.2.12, from 11.3.0 before 11.3.10.
Weaknesses (CWE)
-
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSS scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation status
Exploited in the wild
Recorded 2026-06-01 13:29:38 UTC · CVE
Proof of concept available
Recorded 2026-06-07 12:20:10 UTC · GitHub
References
Known exploited vulnerability sources
Catalogues that list this CVE as a known exploited vulnerability.
| Source | Added |
|---|---|
| CVE First | 2026-06-01 13:29 UTC |
| CISA | 2026-06-02 14:00 UTC |
Scanner integrations
| Scanner | Reference | Detected |
|---|---|---|
| Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-9082.yaml | Jun 01, 2026 |
Potential proof of concepts
These PoCs are unverified and could contain malware. Use at your own risk.
github · Created 2026-06-07 12:20:10 UTC · 0 stars
Drupal Core PostgreSQL SQLi to RCE via /user/login (CVE-2026-9082 / SA-CORE-2026-004)
github · Created 2026-05-27 10:26:02 UTC · 0 stars
github · Created 2026-05-27 09:11:15 UTC · 0 stars
Passive checker for CVE-2026-9082 / SA-CORE-2026-004 (Drupal core SQL injection, PostgreSQL)
github · Created 2026-05-21 14:46:00 UTC · 1 stars
PoC for CVE-2026-9082 (Drupal SA-CORE-2026-004) Drupal Core SQLi
github · Created 2026-05-21 10:42:30 UTC · 14 stars
Drupal Core PostgreSQL SQL Injection PoC - CVE-2026-9082. Ethical PoC for the Drupal vulnerability allowing anonymous SQL injection through the JSON:API module on PostgreSQL-backed sites.
github · Created 2026-05-21 04:03:42 UTC · 2 stars
CVE-2026-9082 | SA-CORE-2026-004
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Added to KEVIntel
-
Detected by Nuclei
-
KEV confirmed by CISA
-
Proof of Concept Exploit Available