CVE-2026-9082 Details
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.1.10, from 11.2.0 before 11.2.12, from 11.3.0 before 11.3.10.
A highly critical SQL injection vulnerability has been identified in Drupal Core. This issue affects versions 8.9.0 prior to 10.4.10, 10.5.0 prior to 10.5.10, 10.6.0 prior to 10.6.9, 11.0.0 prior to 11.1.10, 11.2.0 prior to 11.2.12, and 11.3.0 prior to 11.3.10. The vulnerability arises from improper sanitization of database queries, allowing attackers to send specially crafted requests that could lead to arbitrary SQL injection on sites using PostgreSQL databases. Exploitation of this vulnerability could result in information disclosure, and in some cases, privilege escalation, remote code execution, or other attacks. Notably, this vulnerability can be exploited by anonymous users.
Users are advised to update to the latest version of Drupal. For Drupal 11.3.x, update to Drupal 11.3.10; for 11.2.x, update to 11.2.12; for 11.1.x or 11.0.x, update to 11.1.10. For Drupal 10.6.x, update to 10.6.9, and for 10.5.x, update to 10.5.10. If using Drupal 9 or 8, manually apply the Drupal 9.5 or 8.9 patch for this issue.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 20, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-9082 | CISA-ADP | US Government Resource |
| https://www.drupal.org/sa-core-2026-004 | [email protected] | PatchVendor Advisory |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Drupal Core SQL Injection Vulnerability | May 22, 2026 | May 27, 2026 | Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| drupal drupal | >= 8.9.0, < 10.4.10 >= 10.5.0, < 10.5.10 >= 10.6.0, < 10.6.9 >= 11.0.0, < 11.1.10 >= 11.2.0, < 11.2.12 >= 11.3.0, < 11.3.10 |
CPE
Remediation
| |
Change History
10 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 22, 2026 | Initial Analysis | [email protected] |
| May 22, 2026 | CVE Modified | CISA-ADP |
| May 22, 2026 | CVE CISA KEV Update | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| May 22, 2026 | CVE Modified | [email protected] |
| May 22, 2026 | CVE Modified | CISA-ADP |
| May 20, 2026 | New CVE Received | [email protected] |
| May 20, 2026 | CVE Modified | CISA-ADP |