CVE-2026-9082
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.1.10, from 11.2.0 before 11.2.12, from 11.3.0 before 11.3.10.
- Affected products
- Drupal, Postgresql
- Drupal
- < 10.4.10, 10.5.10, 10.6.9, 11.1.10, 11.2.12, 11.3.10
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 88.3% (100th percentile)
- Weakness
- CWE-89
- NVD status
- Analyzed
- Published
- 2026-05-20
- Attack patterns
- CAPEC-66
- Entry point
- filter[a][condition][value][<injected-key>] query param
- Path
- /jsonapi/node/article
CVE-2026-9082 at NVD
32 known exploits for CVE-2026-9082
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2026-9082
CVE-2026-9082-Mass_Scanner
CVE-2026-9082-PoC
drupal-cve-2026-9082-checker
CVE-2026-9082
cve-2026-9082
CVE-2026-9082
CVE-2026-9082
cve-2026-9082-drupal-postgresql-rce
portfolio-drupal-cve-2026-9082
CVE-2026-9082
CVE-2026-PoCs
CVE-2026-9082-Drupal-PoC
drupal-jsonapi-sqli-scanner
π Drupal Core 11.3.9 Anonymous Blind SQL Injection
Exploit for CVE-2026-63030
--POC
Exploit for SQL Injection in Drupal
π Drupal core 10.5.5 JSON:API PostgreSQL Error-Based SQL Injection
Exploit for SQL Injection in Drupal
π Drupal core 10.5.5 SQL Injection
Drupal Core 10.5.5 - Error-Based SQL Injection
Exploit for SQL Injection in Drupal
Exploit for SQL Injection in Drupal
patch-to-exploit
Exploit for CVE-2026-9082
Exploit for CVE-2026-9082
Exploit for CVE-2026-9082
Exploit for CVE-2026-9082
Exploit for CVE-2026-9082
CVE-2026-9082
Drupal Core PostgreSQL EntityQuery SQL Injection