Drupal Vulnerability in Hacker Crosshairs Shortly After Disclosure

https://www.securityweek.com/wp-content/uploads/2026/05/Drupal.jpg

Drupal is warning users that it’s already seeing attempts to exploit CVE-2026-9082, the highly critical vulnerability patched this week.

The vulnerability affects an API designed to ensure that database queries are sanitized to prevent SQL injection.

“A vulnerability in this API allows an attacker to send specially crafted requests, resulting in arbitrary SQL injection for sites using PostgreSQL databases,” Drupal explains.

The flaw can be exploited by unauthenticated attackers to obtain information and in some cases for privilege escalation and remote code execution.

Drupal predicted that an exploit for CVE-2026-9082 may be created within hours or days of disclosure and alerted users prior to the patch’s release on May 20.

The CMS powers hundreds of thousands of websites, but the security hole only impacts sites that use PostgreSQL, and Drupal believes less than 5% are affected.

Advertisement. Scroll to continue reading.

However, the advisory for CVE-2026-9082was updated on March...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE

Read more