CRITICALCVSS 9.8Vulnerability
CVE-2026-9082
Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.
Properties
- severity
- CRITICAL
- product
- Core
- vulnerabilityName
- Drupal Core SQL Injection Vulnerability
- cvss_score
- 9.8
- epss_score
- 0.88319
- dueDate
- 2026-05-27
- requiredAction
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- dateAdded
- 2026-05-22
- cve_id
- CVE-2026-9082
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- vendorProject
- Drupal
- epss_percentile
- 0.99759
Related Entities (3)
ENRICHED_BY (1)
→[Source]FIRST EPSS
DESCRIBES (1)
←[KEVEntry]Drupal Core SQL Injection Vulnerability
KNOWN_EXPLOITED (1)
→[Source]CISA KEV
Explore deeper with Ninja Signal's threat intelligence graph