CVE-2026-55804 Details
Description
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.
A vulnerability allowing object injection through improperly controlled modification of dynamically-determined object attributes has been identified in Drupal Core. This issue affects versions prior to 10.5.12, versions 10.6.0 through 10.6.11, versions 11.2.0 through 11.2.14, versions 11.3.0 through 11.3.12, as well as Drupal 11.0.* and 11.1.*. The vulnerability arises from a gadget chain that could be exploited if an insecure deserialization vulnerability is present, allowing for remote code execution or SQL injection.
Users are advised to update to the latest version of Drupal. For Drupal 11, update to version 11.3.12 or 11.2.14. For Drupal 10, update to version 10.6.11 or 10.5.12. Versions 11.1.x, 11.0.x, and 10.4.x and below are end-of-life and do not receive security coverage.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.drupal.org/sa-core-2026-006 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-915 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| drupal drupal | < 10.5.12 >= 10.6.0, < 10.6.11 >= 11.0.0, < 11.2.14 >= 11.3.0, < 11.3.12 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 16, 2026 | Initial Analysis | [email protected] |
| Jul 13, 2026 | CVE Modified | CISA-ADP |
| Jul 10, 2026 | New CVE Received | [email protected] |