CVE-2026-55804: Drupal core - Moderately critical - Gadget chain - SA-CORE-2026-006
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0., from 0.0.0 to 11.1..
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Drupal coreto a version that resolves this vulnerability.Fixed in 10.5.12 - Upgrade
Upgrade
Drupal coreto a version that resolves this vulnerability.Fixed in 10.6.11 - Upgrade
Upgrade
Drupal coreto a version that resolves this vulnerability.Fixed in 11.2.14 - Upgrade
Upgrade
Drupal coreto a version that resolves this vulnerability.Fixed in 11.3.12 - Upgrade
Upgrade
Drupal coreto a version that resolves this vulnerability.Fixed in 11.0.* - Upgrade
Upgrade
Drupal coreto a version that resolves this vulnerability.Fixed in 11.1.* - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch SA-CORE-2026-006
Event History
Frequently Asked Questions
What is the severity of CVE-2026-55804?
The severity of CVE-2026-55804 is classified as moderately critical with a risk score of 72.
How do I fix CVE-2026-55804?
To fix CVE-2026-55804, update your Drupal core to a version that is not affected, specifically versions 10.5.13, 10.6.12, 11.2.15, and 11.3.13 or later.
What versions of Drupal are affected by CVE-2026-55804?
CVE-2026-55804 affects Drupal core versions from 0.0.0 to 10.5.12, 10.6.0 to 10.6.11, 11.2.0 to 11.2.14, and 11.3.0 to 11.3.12.
What exploit does CVE-2026-55804 enable?
CVE-2026-55804 enables Object Injection due to improperly controlled modification of dynamically-determined object attributes in Drupal.
When was CVE-2026-55804 published?
CVE-2026-55804 was published on July 10, 2026.