CVE-2026-9082
Drupal Core SQL Injection Vulnerability
CVSS
9.8
Crítico
EPSS
87.9%
p100
KEV
SÍ
22 may 2026
Exploit Today
80
0-100
Publicado: 20 may 2026 · Última mod.: 23 jul 2026 · CWE-89
Producto
Drupal / Core
Vulnerabilidad
Drupal Core SQL Injection Vulnerability
Añadido a KEV
22 may 2026
Remediar antes de
27 may 2026
Uso conocido en ransomware
No
Descripción resumida
Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.
Acción requerida
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notas
https://www.drupal.org/sa-core-2026-004 ; https://nvd.nist.gov/vuln/detail/CVE-2026-9082
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.1.10, from 11.2.0 before 11.2.12, from 11.3.0 before 11.3.10.