CVE-2026-6366 Details
Description
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core: from 8.0.0 before 10.5.9, from 10.6.0 before 10.6.7, from 11.0.0 before 11.2.11, from 11.3.0 before 11.3.7.
A vulnerability allowing improper control over the modification of dynamically-determined object attributes has been identified in Drupal Core. This issue affects versions 8.0.0 prior to 10.5.9, 10.6.0 prior to 10.6.7, 11.0.0 prior to 11.2.11, and 11.3.0 prior to 11.3.7. The vulnerability allows object injection through a 'gadget chain' that could be exploited if an insecure deserialization vulnerability is present on the site. While this issue does not pose a direct threat, it could lead to remote code execution or SQL injection by exploiting another vulnerability that allows the application to deserialize untrusted data.
Users can update to the latest version of Drupal to address this vulnerability. Instructions for updating are available on the Drupal project page. Note that Drupal versions 11.1.x, 11.0.x, and 10.4.x and below are end-of-life and do not receive security coverage.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.drupal.org/sa-core-2026-002 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-915 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| drupal drupal | >= 8.0.0, < 10.5.9 >= 10.6.0, < 10.6.7 >= 11.0.0, < 11.2.11 >= 11.3.0, < 11.3.7 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 20, 2026 | Initial Analysis | [email protected] |
| May 20, 2026 | CVE Modified | CISA-ADP |
| May 19, 2026 | New CVE Received | [email protected] |