---
id: CVE-2026-9082
title: >-
  Improper Neutralization of Special Elements used in an SQL Command ('SQL
  Injection') vulnerability in Drupal Drupal core allows SQL Injection.


  This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before
  10.5.10, from 1…
summary: >-
  Improper Neutralization of Special Elements used in an SQL Command ('SQL
  Injection') vulnerability in Drupal Drupal core allows SQL Injection.


  This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before
  10.5.10, from 1…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-89
vendor: drupal
product: drupal
affected:
  - 'drupal >= 8.9.0, < 10.4.10'
  - 'drupal >= 10.5.0, < 10.5.10'
  - 'drupal >= 10.6.0, < 10.6.9'
  - 'drupal >= 11.0.0, < 11.1.10'
  - 'drupal >= 11.2.0, < 11.2.12'
  - 'drupal >= 11.3.0, < 11.3.10'
patched:
  - drupal 11.3.10
published: '2026-05-20'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T19:17:45.637'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-9082'
references:
  - url: 'https://www.drupal.org/sa-core-2026-004'
    label: mlhess@drupal.org
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-9082
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - in-the-wild
  - exploit-available
  - kev
exploited: true
exploitAvailable: true
ssvc:
  exploitation: active
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-05-23T03:55:40.059743Z'
epss: 0.15701
epssPercentile: 0.96771
kev: true
kevDateAdded: '2026-05-22'
kevDueDate: '2026-05-27'
kevRansomware: false
exploits:
  exploitdb: true
  github: 12
  githubRepos:
    - 'https://github.com/7h30th3r0n3/CVE-2026-9082-Drupal-PoC'
    - 'https://github.com/ambionics/cve-2026-9082-drupal-postgresql-rce'
    - 'https://github.com/N45HT/drupal-cve-2026-9082-checker'
  metasploit:
    - auxiliary/scanner/http/drupal_pgsql_entityquery_sqli
  nuclei:
    - CVE-2026-9082
  checkedAt: '2026-10-07T20:47:22.833Z'
ingestedAt: '2026-10-07T20:46:46.954Z'
---

## Overview

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection.

This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.1.10, from 11.2.0 before 11.2.12, from 11.3.0 before 11.3.10.

## Affected

- `drupal >= 8.9.0, < 10.4.10`
- `drupal >= 10.5.0, < 10.5.10`
- `drupal >= 10.6.0, < 10.6.9`
- `drupal >= 11.0.0, < 11.1.10`
- `drupal >= 11.2.0, < 11.2.12`
- `drupal >= 11.3.0, < 11.3.10`

## Remediation

Upgrade past the affected range:

- `drupal 11.3.10`
