Vulnerability record · CVE-2026-9082 · published 20 May 2026
CVE-2026-9082: Drupal core SQL injection in unauthenticated request path
DDrupal · Drupal
Drupal core contains a SQL injection flaw (CWE-89) caused by improper neutralization of special elements in SQL commands. It affects multiple core branches from 8.9.0 through the 11.3.x line, with fixes available in the listed patched releases. Because it is remotely reachable without authentication and rated 9.8, it is a high-value target for mass exploitation.
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.1.10, from 11.2.0 before 11.2.12, from 11.3.0 before 11.3.10.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable SQL injection with CVSS 9.8, active KEV listing, and near-maximum EPSS makes this an urgent patch-first issue.
What it is
Drupal core contains a SQL injection flaw (CWE-89) caused by improper neutralization of special elements in SQL commands. It affects multiple core branches from 8.9.0 through the 11.3.x line, with fixes available in the listed patched releases. Because it is remotely reachable without authentication and rated 9.8, it is a high-value target for mass exploitation.
Impact
An unauthenticated attacker can inject SQL through the vulnerable request path, potentially reading, modifying, or deleting database contents and, depending on database privileges, executing database-level operations. Full compromise of confidentiality, integrity, and availability of the Drupal site and its data is possible.
Attack surface
Reachable over the network via HTTP with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The description does not name the specific endpoint or parameter, so the exact injection point is not documented in this record.
Exploitation
CVE-2026-9082 was added to CISA KEV on 2026-05-22 with a 2026-05-27 remediation due date, indicating known exploitation in the wild. EPSS is 0.87892 (99.75th percentile), and no ransomware campaign use is documented.
What to do
- Upgrade Drupal core to a fixed release: 10.4.10, 10.5.10, 10.6.9, 11.1.10, 11.2.12, or 11.3.10, matching your branch.
- If immediate patching is not possible, apply the vendor mitigation guidance in Drupal SA-CORE-2026-004 or take the site offline.
- Follow CISA BOD 22-01 guidance for cloud-hosted instances and meet the 2026-05-27 KEV due date.
- Restrict database account privileges used by Drupal to the minimum needed, limiting the blast radius of successful injection.
- Review web server and WAF logs for SQL injection patterns against Drupal endpoints and block known malicious request signatures.
Detection
- Search web and WAF logs for SQL metacharacters (quotes, UNION, OR 1=1, comment sequences) in requests to Drupal paths.
- Monitor database logs for anomalous queries, errors, or unexpected schema and data access originating from the web tier.
- Alert on unexpected changes to Drupal users, roles, or content that could indicate post-exploitation activity.
- Correlate outbound connections from the Drupal host to unfamiliar destinations, which may indicate data exfiltration.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-9082 to the Known Exploited Vulnerabilities catalog on 22 May 2026 as "Drupal Core SQL Injection Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 27 May 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.drupal.org/sa-core-2026-004 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-9082 | US Government Resource |
Track CVE-2026-9082 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-9082), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.