Drupal Patches Highly Critical Vulnerability Exposing Websites to Hacking
Briefly

Drupal Patches Highly Critical Vulnerability Exposing Websites to Hacking
Drupal has released patches for a highly critical vulnerability, CVE-2026-9082, affecting an API that sanitizes database queries to prevent SQL injection. The flaw allows attackers to send specially crafted requests that result in arbitrary SQL injection for sites using PostgreSQL databases. Exploitation can occur without authentication to obtain information, and in some cases can enable privilege escalation and remote code execution. The issue only impacts Drupal installations configured with PostgreSQL. Patches are available for Drupal 11.3, 11.2, 10.6, and 10.5.x. Updates also address important upstream vulnerabilities in Symfony and Twig that may affect Drupal depending on site configuration and contrib modules.
"A vulnerability in this API allows an attacker to send specially crafted requests, resulting in arbitrary SQL injection for sites using PostgreSQL databases. Drupal warns that the flaw can be exploited without authentication to obtain information and in some cases for privilege escalation and remote code execution."
"The developers of the CMS had alerted users prior to the patch's release that an exploit might be created within hours or days of disclosure. The vulnerability, tracked as CVE-2026-9082 and rated 'highly critical' with a NIST CMSS score of 20 out of 25, affects an API designed to ensure that database queries are sanitized to prevent SQL injection attacks."
"Drupal powers hundreds of thousands of websites, but CVE-2026-9082 only affects sites that use PostgreSQL. Patches are available for Drupal versions 11.3, 11.2, 10.6, and 10.5.x. The latest updates also address 'important' vulnerabilities in Symfony and Twig that affect Drupal."
"Depending on your site configuration and contrib modules, you may be vulnerable to one or more of these upstream issues, so updating these dependencies is highly recommended whether the SQL Injection vulnerability affects you or not. Vulnerabilities are regularly patched in Drupal, but few of them are severe, and there hasn't been a 'highly critical' flaw in years."
Read at SecurityWeek
Unable to calculate read time
[
|
]