#vulns.comcp

← CVE intelligence

CVE-2026-9082 — Drupal Core SQL Injection Vulnerability

Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.

Severity
critical
Product
Drupal Core
Published
2026-05-22
EPSS
0.879
CISA KEV
Known exploited
Ransomware
Known campaign use

References and validation

Entries are refreshed from CISA KEV and FIRST EPSS. Validate applicability before testing.