CRITICALCVSS 9.8Vulnerability

CVE-2026-9082

Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.

Properties

severity
CRITICAL
product
Core
vulnerabilityName
Drupal Core SQL Injection Vulnerability
cvss_score
9.8
epss_score
0.88319
dueDate
2026-05-27
requiredAction
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
dateAdded
2026-05-22
cve_id
CVE-2026-9082
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendorProject
Drupal
epss_percentile
0.99759

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

DESCRIBES (1)

[KEVEntry]Drupal Core SQL Injection Vulnerability

KNOWN_EXPLOITED (1)

[Source]CISA KEV

Explore deeper with Ninja Signal's threat intelligence graph