SA-CORE-2026-005: Critical severity Drupal Drupal vulnerability

Published Jun 17, 2026
·
Updated

SA-CORE-2019-003 added protection for fields that store serialized data to disallow direct writes via web services. The above fix did not cover all potential attack vectors for JSON:API. An attacker with appropriate JSON:API write permission could potentially inject a malicious payload in certain rare circumstances, potentially resulting in PHP Object Injection. This vulnerability is mitigated by the fact that in order to be exploitable:

A site must use an entity reference field type that stores a serialized property. An attacker must have permission to write to the entity via JSON:API.

No field type shipped with Drupal core meets these criteria, and contributed or user-created field types that do appear to be extremely unusual. This update protects all such fields; no changes are required in contributed modules. JSON:API is read-only by default, so sites are only affected if they have enabled write access (either through administrator configuration or the installation of a contributed or custom module that enables write access). Drupal Steward protection: This issue is being protected by Drupal Steward. In this instance, we believe that the WAF rule will provide mitigation for the common/obvious vulnerability paths, but may not cover all cases or work for all hosting providers. Additionally, several other core security advisories released today are not mitigated by Drupal Steward. Therefore, our recommended action is still to plan an actual Drupal update within 24 hours of this release.

Credit

Michael Maturi (michaelmaturi)

Affected Software

1 affected componentFixes available
Drupal Drupal<11.3.12, <11.2.14, <10.6.11, <10.5.12
11.3.1211.2.1410.6.1110.5.12

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 11.3.12Fixed in 11.2.14Fixed in 10.6.11Fixed in 10.5.12
  2. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Patch SA-CORE-2019-003
  3. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 11.3.12
  4. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 11.2.14
  5. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 10.6.11
  6. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 10.5.12
  7. Configuration

    Disable JSON:API write access if it is not required. JSON:API is read-only by default; sites are only affected if write access has been enabled.

    JSON:API write_access = disabled
  8. Compensating control

    Enable or ensure the Drupal Steward WAF rule is deployed by your hosting/provider to mitigate common exploit paths. Note this may not cover all cases and is not a substitute for applying the update.

  9. Operational

    Plan and apply the actual Drupal update within 24 hours of this release.

Event History

Jun 17, 2026
Advisory Published
via Drupal·12:00 AM
Data Sourced
via Drupal·12:00 AM
DescriptionSeverityAffected Software

Child vulnerabilities

Contains the following vulnerabilities.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of SA-CORE-2026-005?

The severity of SA-CORE-2026-005 is critical with a score of 9.

2

How do I fix SA-CORE-2026-005?

To fix SA-CORE-2026-005, ensure that you are running the latest version of Drupal that addresses this vulnerability.

3

What are the potential risks associated with SA-CORE-2026-005?

The risks associated with SA-CORE-2026-005 include potential unauthorized injection of malicious payloads via JSON:API by attackers with write permissions.

4

What systems are affected by SA-CORE-2026-005?

SA-CORE-2026-005 affects systems running Drupal that utilize JSON:API with inappropriate permissions.

5

When was SA-CORE-2026-005 published?

SA-CORE-2026-005 was published on June 17, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203