CVE-2026-9082 CRITICAL

Drupal Core Vulnerability
Generated: 10 Oct 2026 20:36 • CVE Threat Intelligence

Description

Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.

9.8
CVSS CRITICAL

Details

Published
22 May 2026 00:00
Modified
N/A
Source
CIRCL
Vendor
Drupal
Product
Core
Fix Version
Vendor Patch / Mitigation Available