CVE-2026-9082
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection.
This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.1.10, from 11.2.0 before 11.2.12, from 11.3.0 before 11.3.10.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
SQL injection in Drupal core's database abstraction API allows unauthenticated attackers to execute arbitrary SQL on PostgreSQL databases, leading to information disclosure and potential RCE.
Vulnerability
Drupal core's database abstraction API fails to properly neutralize special elements in SQL commands, resulting in a SQL injection vulnerability [1]. The issue affects all Drupal versions from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.1.10, from 11.2.0 before 11.2.12, and from 11.3.0 before 11.3.10. The vulnerability is only exploitable on sites using PostgreSQL databases [1].
Exploitation
An attacker can exploit this vulnerability without authentication or user interaction by sending specially crafted requests to the vulnerable Drupal site [1]. The attack requires network access to the site and targets the database abstraction layer, which fails to sanitize input before constructing SQL queries [1].
Impact
Successful exploitation allows an attacker to perform arbitrary SQL injection, leading to information disclosure, privilege escalation, remote code execution, or other attacks [1]. The impact can affect all data managed by the Drupal site, potentially compromising the entire application [1].
Mitigation
Drupal has released fixed versions: 11.3.10, 11.2.12, 11.1.10, 10.6.9, 10.5.10, and 10.4.10 [1]. Administrators should update to the appropriate patched version immediately. The advisory also includes security updates for Symfony and Twig dependencies, which are recommended regardless of PostgreSQL usage [1]. No workarounds are provided; updating is the only mitigation [1].
AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: >=8.9.0 <10.4.10 || >=10.5.0 <10.5.10 || >=10.6.0 <10.6.9 || >=11.0.0 <11.1.10 || >=11.2.0 <11.2.12 || >=11.3.0 <11.3.10
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
1- Drupal core - Highly critical - SQL injection - SA-CORE-2026-004Drupal Security Advisories · May 20, 2026