{"cvss":0.0,"datePublished":"2026-05-22","dateUpdated":"2026-05-22","description":"Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.","dueDate":"2026-05-27","id":"CVE-2026-9082","kev_catalogs":["cisa"],"knownRansomwareCampaignUse":"Unknown","notes":"https://www.drupal.org/sa-core-2026-004 ; https://nvd.nist.gov/vuln/detail/CVE-2026-9082","product":"Core","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","severity":"HIGH","source":"cisa_known_exploited","title":"Drupal Core SQL Injection Vulnerability","vendor":"Drupal"}