KEVIntel
9.8
CVSS
Critical

CVE-2026-9082

PUBLISHED

Drupal core - Highly critical - SQL injection - SA-CORE-2026-004

1 day faster than CISA KEV

Exploited in the wild PoC available Remote Low complexity No user interaction
Vendor
Drupal
Product
Drupal core
Published
May 20, 2026
EPSS
10.4% · 93% pctl

Automate this intelligence with the Pro API

Everything on this page — CVSS, EPSS, exploit status, PoCs, scanner integrations, mentions, tags, and immediate honeypot data — is available programmatically for VM, SOC, and CTI workflows.

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.1.10, from 11.2.0 before 11.2.12, from 11.3.0 before 11.3.10.

drupal cisa nuclei_scanner

Weaknesses (CWE)

  • Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CVSS scores

CVSS v3.1 9.8 Critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploitation status

Exploited in the wild

Recorded 2026-06-01 13:29:38 UTC · CVE

Proof of concept available

Recorded 2026-06-07 12:20:10 UTC · GitHub

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CVE First 2026-06-01 13:29 UTC
CISA 2026-06-02 14:00 UTC

Scanner integrations

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

11romain/CVE-2026-9082

github · Created 2026-06-07 12:20:10 UTC · 0 stars

Drupal Core PostgreSQL SQLi to RCE via /user/login (CVE-2026-9082 / SA-CORE-2026-004)

thinhap/CVE-2026-9082-PoC

github · Created 2026-05-27 10:26:02 UTC · 0 stars

strobelpierre/CVE-2026-9082

github · Created 2026-05-27 09:11:15 UTC · 0 stars

Passive checker for CVE-2026-9082 / SA-CORE-2026-004 (Drupal core SQL injection, PostgreSQL)

ywh-jfellus/CVE-2026-9082

github · Created 2026-05-21 14:46:00 UTC · 1 stars

PoC for CVE-2026-9082 (Drupal SA-CORE-2026-004) Drupal Core SQLi

7h30th3r0n3/CVE-2026-9082-Drupal-PoC

github · Created 2026-05-21 10:42:30 UTC · 14 stars

Drupal Core PostgreSQL SQL Injection PoC - CVE-2026-9082. Ethical PoC for the Drupal vulnerability allowing anonymous SQL injection through the JSON:API module on PostgreSQL-backed sites.

0xBlackash/CVE-2026-9082

github · Created 2026-05-21 07:26:11 UTC · 1 stars

CVE-2026-9082

HORKimhab/CVE-2026-9082

github · Created 2026-05-21 04:03:42 UTC · 2 stars

CVE-2026-9082 | SA-CORE-2026-004

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Detected by Nuclei

  • KEV confirmed by CISA

  • Proof of Concept Exploit Available