{"id":"CVE-2026-9082","title":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection.\n\nThis issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 1…","summary":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection.\n\nThis issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 1…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-89"],"vendor":"drupal","product":"drupal","affected":["drupal >= 8.9.0, < 10.4.10","drupal >= 10.5.0, < 10.5.10","drupal >= 10.6.0, < 10.6.9","drupal >= 11.0.0, < 11.1.10","drupal >= 11.2.0, < 11.2.12","drupal >= 11.3.0, < 11.3.10"],"patched":["drupal 11.3.10"],"published":"2026-05-20","updated":"2026-10-07","sourceUpdated":"2026-10-07T19:17:45.637","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-9082","references":[{"url":"https://www.drupal.org/sa-core-2026-004","label":"mlhess@drupal.org"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-9082","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","cve.org","in-the-wild","exploit-available","kev"],"exploited":true,"exploitAvailable":true,"ssvc":{"exploitation":"active","automatable":"yes","technicalImpact":"total","timestamp":"2026-05-23T03:55:40.059743Z"},"epss":0.15701,"epssPercentile":0.96771,"kev":true,"kevDateAdded":"2026-05-22","kevDueDate":"2026-05-27","kevRansomware":false,"exploits":{"exploitdb":true,"github":12,"githubRepos":["https://github.com/7h30th3r0n3/CVE-2026-9082-Drupal-PoC","https://github.com/ambionics/cve-2026-9082-drupal-postgresql-rce","https://github.com/N45HT/drupal-cve-2026-9082-checker"],"metasploit":["auxiliary/scanner/http/drupal_pgsql_entityquery_sqli"],"nuclei":["CVE-2026-9082"],"checkedAt":"2026-10-07T20:47:22.833Z"},"ingestedAt":"2026-10-07T20:46:46.954Z","slug":"CVE-2026-9082","body":"## Overview\n\nImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection.\n\nThis issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.1.10, from 11.2.0 before 11.2.12, from 11.3.0 before 11.3.10.\n\n## Affected\n\n- `drupal >= 8.9.0, < 10.4.10`\n- `drupal >= 10.5.0, < 10.5.10`\n- `drupal >= 10.6.0, < 10.6.9`\n- `drupal >= 11.0.0, < 11.1.10`\n- `drupal >= 11.2.0, < 11.2.12`\n- `drupal >= 11.3.0, < 11.3.10`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `drupal 11.3.10`","depth":"hadal","depthScore":82,"depthScoreParts":{"impact":53.9,"likelihood":3.1,"exploitation":25,"ransomware":0},"changes":[]}