CVE-2026-9082: critical vulnerability in Drupal core
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Drupal has a critical SQL injection flaw that lets attackers bypass security and directly manipulate the database by injecting malicious code into database queries. This allows them to steal, modify, or delete sensitive data on affected websites.
SQL injection vulnerability in Drupal core due to improper neutralization of special elements in SQL commands. Affects multiple versions (8.9.0–10.4.9, 10.5.0–10.5.9, 10.6.0–10.6.8, 11.0.0–11.1.9, 11.2.0–11.2.11, 11.3.0–11.3.9). Successful exploitation enables database manipulation, data exfiltration, and potential code execution depending on database permissions.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.