CVE-2026-9082: Drupal Core SQL Injection Vulnerability
Published May 20, 2026
·Updated
Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.
Affected Software
8 affected components
Drupal Drupal Core>=8.9.0<10.4.10, >=10.5.0<10.5.10, >=10.6.0<10.6.9, >=11.0.0<11.1.10, >=11.2.0<11.2.12, >=11.3.0<11.3.10
Drupal Core
Drupal Drupal>=8.9.0<10.4.10
Drupal Drupal>=10.5.0<10.5.10
Drupal Drupal>=10.6.0<10.6.9
Drupal Drupal>=11.0.0<11.1.10
Drupal Drupal>=11.2.0<11.2.12
Drupal Drupal>=11.3.0<11.3.10
Remediation
Information
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Patch Available
Event History
May 20, 2026
CVE Published
via MITRE·06:20 PM
Data Sourced
via MITRE·06:20 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
May 22, 2026
Known Exploited
via CISA·12:00 AM
Data Sourced
via CISA·12:00 AM
RemedyDescriptionAffected Software
News Published
via BleepingComputer·01:14 PM
News Published
via BleepingComputer·01:17 PM
May 26, 2026
News Published
via BleepingComputer·08:46 AM
Jun 1, 2026
Exploit Published
via ExploitDB·12:00 AM
Aug 4, 58402
Event
via FIRST·05:37 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-9082?
CVE-2026-9082 is classified as a highly critical SQL injection vulnerability in Drupal core.
2
How do I fix CVE-2026-9082?
To fix CVE-2026-9082, you should update your Drupal core to the latest version specified in the security advisory.
3
Which versions of Drupal are affected by CVE-2026-9082?
CVE-2026-9082 affects Drupal core versions from 8.9.0 up to but not including 10.4.10, as well as several other specified versions.
4
What type of vulnerability is CVE-2026-9082?
CVE-2026-9082 is an SQL injection vulnerability that allows attackers to manipulate SQL commands.
5
Is CVE-2026-9082 publicly disclosed?
Yes, CVE-2026-9082 has been publicly disclosed and is documented in a security advisory.