CVE-2026-9082criticalunder attackCWE-89

CVE-2026-9082: critical vulnerability in Drupal core

Drupal core - Highly critical - SQL injection - SA-CORE-2026-004

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 9.8epss 16%
from disclosure to weapon1 days
Published on NVDMay 20
1st PoC+1d
metasploitMay 20
CISA KEV+2d
exploitation probability
16%top 3% of all CVEs
observed exploitation
yesCISA + VulnCheck
24 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Not affected
1 product — because the vulnerable code is not present in the product
red_hat_products
Action required by CISAfederal deadline: 2026-05-27

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

In short

Drupal has a critical SQL injection flaw that lets attackers bypass security and directly manipulate the database by injecting malicious code into database queries. This allows them to steal, modify, or delete sensitive data on affected websites.

Technical detail

SQL injection vulnerability in Drupal core due to improper neutralization of special elements in SQL commands. Affects multiple versions (8.9.0–10.4.9, 10.5.0–10.5.9, 10.6.0–10.6.8, 11.0.0–11.1.9, 11.2.0–11.2.11, 11.3.0–11.3.9). Successful exploitation enables database manipulation, data exfiltration, and potential code execution depending on database permissions.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.1.10, from 11.2.0 before 11.2.12, from 11.3.0 before 11.3.10.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Drupal · Drupal core
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.