RaqibCTI
CVE

CVE-2026-9082

P2
Drupal Core SQL Injection Vulnerability
Drupal · Core
Date added (CISA)
2026-05-22
Remediation due
2026-05-27
Known ransomware use
Not indicated
Remediation priority
P2past CISA due date

Description

Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.

Source: NVD ↗ · CISA KEV Catalog ↗

CVE-2026-9082: Drupal Core SQL Injection Vulnerability · RaqibCTI