Skip to content
COOEY

EXPOSURES › CVE-2026-9082

CVE-2026-9082

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-05-22 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-9082 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 65/100 rceexploited-in-wildunpatched

Drupal Core SQL injection vulnerability enables remote code execution and privilege escalation via database API.

Drupal Core contains a SQL injection flaw in the database abstraction API that allows attackers to execute arbitrary commands and escalate privileges. This poses a severe risk to DIB organizations using Drupal-based systems, as it enables remote code execution and could lead to data exfiltration or system compromise. Organizations must immediately patch the vulnerability and audit all Drupal deployments for exposure.

Shame score — A critical SQL injection vulnerability in a widely-used CMS core component enables remote code execution and privilege escalation, representing a significant security risk for DIB organizations.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.