Drupal Core Vulnerability
Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.
CVSS Score
9.8
CRITICAL
Published
22 May 2026 00:00
Modified
N/A
Vendor
Drupal
Product
Core
Source
CIRCL
Affected Versions
Fix
Vendor Patch / Mitigation Available
Weaknesses (CWE)
CWE-89
Affected Systems
Drupal
Core
Drupal
Core
External Links
KEV Status
Known Exploited Vulnerability