CVE-2026-9082: Drupal Core SQL Injection Vulnerability
Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.
Other sources
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection.
This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.1.10, from 11.2.0 before 11.2.12, from 11.3.0 before 11.3.10.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Drupal coreto a version that resolves this vulnerability.Fixed in 10.4.10 - Upgrade
Upgrade
Drupal coreto a version that resolves this vulnerability.Fixed in 10.5.10 - Upgrade
Upgrade
Drupal coreto a version that resolves this vulnerability.Fixed in 10.6.9 - Upgrade
Upgrade
Drupal coreto a version that resolves this vulnerability.Fixed in 11.1.10 - Upgrade
Upgrade
Drupal coreto a version that resolves this vulnerability.Fixed in 11.2.12 - Upgrade
Upgrade
Drupal coreto a version that resolves this vulnerability.Fixed in 11.3.10 - Compensating control
Use SA-CORE-2026-004 mitigations per vendor instructions. If mitigations are unavailable, discontinue use of Drupal core.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9082?
CVE-2026-9082 is classified as a highly critical SQL injection vulnerability in Drupal core.
How do I fix CVE-2026-9082?
To fix CVE-2026-9082, you should update your Drupal core to the latest version specified in the security advisory.
Which versions of Drupal are affected by CVE-2026-9082?
CVE-2026-9082 affects Drupal core versions from 8.9.0 up to but not including 10.4.10, as well as several other specified versions.
What type of vulnerability is CVE-2026-9082?
CVE-2026-9082 is an SQL injection vulnerability that allows attackers to manipulate SQL commands.
Is CVE-2026-9082 publicly disclosed?
Yes, CVE-2026-9082 has been publicly disclosed and is documented in a security advisory.