Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
1917 articles · 155851 vulns · 36/41 feeds (7d)
← Back to list
9.8
CVE-2026-9082KEVEXPLOITEDPATCHED
drupal · drupal

Drupal core - Highly critical - SQL injection - SA-CORE-2026-004

Description

The security flaw can be exploited without authentication, allowing attackers to trigger arbitrary SQL injection on PostgreSQL-powered sites via specially crafted requests. Successful exploitation can potentially lead to information disclosure, privilege escalation, and even remote code execution.

Affected Products

VendorProductVersions
drupaldrupal8.9.0, 10.5.0, 10.6.0, 11.0.0, 11.2.0, 11.3.0, multiple versions, 9.5

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
open sourcedrupalcert_advisory90%

References

  • https://www.drupal.org/sa-core-2026-004
  • https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-9082.yaml(exploit, nuclei)

Related News (14 articles)

Tier D
BleepingComputer11h ago
CISA orders feds to patch actively exploited Drupal vulnerability
→ No new info (linked only)
Tier D
Heise Security11h ago
Jetzt patchen! Angreifer nutzen kritische Schadcode-Lücke in Drupal aus
→ No new info (linked only)
Tier B
CERT-FR20h ago
Bulletin d'actualité CERTFR-2026-ACT-023 (26 mai 2026)
→ No new info (linked only)
Tier D
The Hacker News1d ago
⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos
→ No new info (linked only)
Tier D
The Hacker News3d ago
Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV
→ No new info (linked only)
Tier D
SecurityWeek4d ago
Drupal Vulnerability in Hacker Crosshairs Shortly After Disclosure
→ No new info (linked only)
Tier D
BleepingComputer4d ago
Drupal: Critical SQL injection flaw now targeted in attacks
→ No new info (linked only)
Tier E
Reddit r/netsec5d ago
Keys to the Kingdom: Anonymous SQL Injection in Drupal Core (CVE-2026-9082)
→ No new info (linked only)
Tier D
SecurityWeek5d ago
Drupal Patches Highly Critical Vulnerability Exposing Websites to Hacking
→ No new info (linked only)
Tier B
BSI Advisories5d ago
[NEU] [hoch] Drupal Core (PostgreSQL): Schwachstelle ermöglicht Manipulation von Dateien
→ No new info (linked only)
Tier D
The Hacker News5d ago
Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites to RCE Attacks
→ No new info (linked only)
Tier B
CERT-FR5d ago
Vulnérabilité dans Drupal (21 mai 2026)
→ No new info (linked only)
Tier D
CSO Online5d ago
Drupal admins rushing to patch maximum severity SQL injection vulnerability
→ No new info (linked only)
Tier C
VulDB5d ago
CVE-2026-9082 | Drupal up to 11.3.9 sql injection (core-2026-004)
→ No new info (linked only)
CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
10.4.1010.5.1010.6.911.1.1011.2.1211.3.10
CWECWE-89, CWE-79, CVE-2026-9082
PublishedMay 20, 2026
Last enriched6h agov11
Tags
cross-site scriptingxsscriticalweb applicationsql injectionremote code executioninformation disclosureprivilege escalationpostgresqlgamingfinancial servicesCISA KEV
Trending Score158🔥
Source articles14
Independent9
Info Completeness12/14
Missing: epss, iocs

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-8495
Date iCal - Critical - Information disclosure - SA-CONTRIB-2026-037
Trending: 27
MEDIUMCVE-2026-6367EXP
Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-003
Trending: 24
NONECVE-2026-4929EXP
Simple Hierarchical Select (Drupal 7) XSS in term-derived output
Trending: 23
NONECVE-2026-4093EXP
Stored XSS in Drupal 7 Term Reference Tree module (token display templates and term labels)
Trending: 19
MEDIUMCVE-2026-6366EXP
Drupal core - Moderately critical - Gadget Chain - SA-CORE-2026-002
Trending: 18

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 20, 2026
Added to CISA KEV
May 20, 2026
Discovered by ZDM
May 20, 2026
Updated: affectedVersions, severity, tags
May 20, 2026
Updated: affectedVersions, tags
May 21, 2026
Updated: description
May 21, 2026
Updated: description, affectedVersions, tags
May 21, 2026
Updated: description, cweIds
May 21, 2026
Updated: affectedVersions, tags
May 22, 2026
Actively Exploited
May 23, 2026
Exploit Available
May 23, 2026
Patch Available
May 23, 2026
Updated: cvssEstimate, cweIds, tags
May 23, 2026
Updated: description
May 26, 2026
Updated: affectedVersions
May 26, 2026
Updated: cvssEstimate
May 26, 2026

Version History

v11
Last enriched 6h ago
v11Tier B6h ago

Updated CVSS score from 6.5 to 9.8 and noted that no new patch version is available.

cvssEstimate
via CERT-FR
v10Tier D10h ago

Added affected version 9.5 and noted that the patch is available but not specified in the article.

affectedVersions
via Heise Security
v9Tier D11h ago

Updated description with details on exploitation methods and added new IoC and tag related to CISA KEV.

description
via BleepingComputer
v8Tier D3d ago

Updated CVSS score to 6.5, added CISA KEV tag, and included new CWE ID CVE-2026-9082.

cvssEstimatecweIdstags
via The Hacker News
v7Tier D4d ago

Updated description with technical details about PostgreSQL impact, changed CVSS score to 23, and added new tags related to gaming and financial services.

affectedVersionstags
via SecurityWeek
v6Tier B5d ago

Updated description with new technical details and added CVE-2026-9082.

descriptioncweIds
via CERT-FR
v5Tier D5d ago

Updated severity to HIGH, added CVSS estimate of 8.0, and included new affected version 10.5.x along with a more detailed description of the vulnerability.

descriptionaffectedVersionstags
via SecurityWeek
v4Tier D5d ago

Updated description to include potential for remote code execution and confirmed CVSS score of 6.5.

description
via The Hacker News
v3Tier D5d ago

Updated description with more technical details about the vulnerability's impact and exploitability, added affected versions 11.3, 11.2, 10.6, 10.5, 8.9, 9.5, corrected CVSS estimate to 9.8, added MITRE ATT&CK technique T1190, and added tags for remote code execution, information disclosure, and privilege escalation.

affectedVersionstags
via CSO Online
v2Tier C5d ago

Updated affected versions to include 11.3.9, changed severity to CRITICAL, noted no exploit available, and added new tag 'sql injection'.

affectedVersionsseveritytags
via VulDB
v16d ago

Initial creation