← Vulnerability feed

Vulnerability record · CVE-2026-9082 · published 20 May 2026

CVE-2026-9082: Drupal core SQL injection in unauthenticated request path

DDrupal · Drupal

Drupal core contains a SQL injection flaw (CWE-89) caused by improper neutralization of special elements in SQL commands. It affects multiple core branches from 8.9.0 through the 11.3.x line, with fixes available in the listed patched releases. Because it is remotely reachable without authentication and rated 9.8, it is a high-value target for mass exploitation.

9.8 CVSS 3.1 Critical CISA KEV since 22 May 2026 EPSS 16% · top 3.3% CWE-89 · SQL injection
9.8CVSS 3.1 base score
16%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
2References
23 Jul 2026Last modified by NVD

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.1.10, from 11.2.0 before 11.2.12, from 11.3.0 before 11.3.10.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable SQL injection with CVSS 9.8, active KEV listing, and near-maximum EPSS makes this an urgent patch-first issue.

What it is

Drupal core contains a SQL injection flaw (CWE-89) caused by improper neutralization of special elements in SQL commands. It affects multiple core branches from 8.9.0 through the 11.3.x line, with fixes available in the listed patched releases. Because it is remotely reachable without authentication and rated 9.8, it is a high-value target for mass exploitation.

Impact

An unauthenticated attacker can inject SQL through the vulnerable request path, potentially reading, modifying, or deleting database contents and, depending on database privileges, executing database-level operations. Full compromise of confidentiality, integrity, and availability of the Drupal site and its data is possible.

Attack surface

Reachable over the network via HTTP with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The description does not name the specific endpoint or parameter, so the exact injection point is not documented in this record.

Exploitation

CVE-2026-9082 was added to CISA KEV on 2026-05-22 with a 2026-05-27 remediation due date, indicating known exploitation in the wild. EPSS is 0.87892 (99.75th percentile), and no ransomware campaign use is documented.

What to do

  • Upgrade Drupal core to a fixed release: 10.4.10, 10.5.10, 10.6.9, 11.1.10, 11.2.12, or 11.3.10, matching your branch.
  • If immediate patching is not possible, apply the vendor mitigation guidance in Drupal SA-CORE-2026-004 or take the site offline.
  • Follow CISA BOD 22-01 guidance for cloud-hosted instances and meet the 2026-05-27 KEV due date.
  • Restrict database account privileges used by Drupal to the minimum needed, limiting the blast radius of successful injection.
  • Review web server and WAF logs for SQL injection patterns against Drupal endpoints and block known malicious request signatures.

Detection

  • Search web and WAF logs for SQL metacharacters (quotes, UNION, OR 1=1, comment sequences) in requests to Drupal paths.
  • Monitor database logs for anomalous queries, errors, or unexpected schema and data access originating from the web tier.
  • Alert on unexpected changes to Drupal users, roles, or content that could indicate post-exploitation activity.
  • Correlate outbound connections from the Drupal host to unfamiliar destinations, which may indicate data exfiltration.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-9082 to the Known Exploited Vulnerabilities catalog on 22 May 2026 as "Drupal Core SQL Injection Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 27 May 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-9082 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-7602Drupal Core Remote Code Execution via Multiple SubsystemsCVE-2018-7602 is a remote code execution flaw in multiple subsystems of Drupal 7.x and 8.x, related to SA-CORE-2018-002. It allows an attacker to com…KEVEPSS 99%analysed9.8CVE-2018-7600Drupal Core input validation flaw enables remote code executionDrupal core before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 fails to properly validate input across multiple subsystems, al…KEVEPSS 100%analysed8.8CVE-2020-13671Drupal core filename sanitization flaw allows uploaded files to execute as PHPDrupal core fails to properly sanitize certain filenames on uploaded files, so files can be interpreted with the wrong extension and served as the wr…KEVEPSS 35%analysed8.1CVE-2019-6340Drupal Core field types fail to sanitize non-form data, enabling PHP code executionSome field types in Drupal 8.5.x before 8.5.11 and 8.6.x before 8.6.10 do not properly sanitize data arriving from non-form sources, which can lead t…KEVEPSS 92%analysed7.8CVE-2020-28949PEAR Archive_Tar stream-wrapper filename sanitization bypass allows file writeArchive_Tar through 1.4.10 only sanitizes '://' filenames to block phar attacks, so other stream wrappers such as file:// still pass through and can …KEVEPSS 85%analysed7.5CVE-2020-36193PEAR Archive_Tar path traversal via symlink handlingTar.php in Archive_Tar through 1.4.11 fails to adequately check symbolic links, allowing write operations to escape the intended extraction directory…KEVEPSS 71%analysed6.1CVE-2020-11023jQuery DOM manipulation methods XSS via untrusted HTML option elementsjQuery versions 1.0.3 through before 3.5.0 execute untrusted code when HTML containing <option> elements from untrusted sources is passed to DOM mani…KEVEPSS 85%analysed10.0CVE-2009-3352Drupal vulnerabilityMultiple unspecified vulnerabilities in the quota_by_role (Quota by role) module for Drupal have unknown impact and attack vectors.EPSS 2.0%

Source: NIST National Vulnerability Database (record CVE-2026-9082), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.