Zafiyet İstihbaratı

CVE-2026-9082 — Drupal Core SQL Injection Vulnerability

Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.

CVECVE-2026-9082CVSSEPSSExploitCISA KEVVendorDrupalÜrünCore

Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.

CISA tarafından önerilen aksiyon

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Bu içerik yararlı oldu mu?Geri bildirim bu cihazda saklanır; varsayılan olarak sunucuya gönderilmez.