PostgreSQL-targeting SQL injection in Drupal Core enables remote code execution
Summary
Hide ▲
Show ▼
A highly critical SQL injection vulnerability in Drupal Core's database abstraction API can grant unauthenticated attackers remote code execution, privilege escalation, or information disclosure on Drupal sites using PostgreSQL. The flaw, tracked as CVE-2026-9082 with a CVSS score of 6.5, allows arbitrary SQL execution via crafted requests sent to PostgreSQL-backed Drupal installations. Exploitation does not require authentication, affecting only PostgreSQL sites. The issue spans multiple supported Drupal versions and has prompted urgent patching for active branches and manual fixes for end-of-life releases.
Timeline
-
21.05.2026 06:44 1 articles · 4h ago
Critical SQL injection in Drupal Core’s PostgreSQL abstraction API patched across supported versions
A critical SQL injection vulnerability in Drupal Core’s database abstraction API allows unauthenticated attackers to execute arbitrary SQL commands on PostgreSQL-backed Drupal installations. Patches have been issued for active Drupal branches (11.3, 11.2, 10.6, 10.5) and manual fixes provided for end-of-life versions (9.5, 8.9). Drupal 7 and lower branches are unaffected. Immediate updates are required to prevent potential remote code execution and privilege escalation.
Show sources
- Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites to RCE Attacks — thehackernews.com — 21.05.2026 06:44
Information Snippets
-
CVE-2026-9082 is an SQL injection vulnerability residing in Drupal Core's database abstraction API that validates queries against PostgreSQL databases.
First reported: 21.05.2026 06:441 source, 1 articleShow sources
- Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites to RCE Attacks — thehackernews.com — 21.05.2026 06:44
-
Exploitation can lead to remote code execution, privilege escalation, or information disclosure without requiring authentication.
First reported: 21.05.2026 06:441 source, 1 articleShow sources
- Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites to RCE Attacks — thehackernews.com — 21.05.2026 06:44
-
Impacted Drupal versions include 11.3.10, 11.2.12, 11.1.10, 10.6.9, 10.5.10, and 10.4.10; Drupal 7 is unaffected.
First reported: 21.05.2026 06:441 source, 1 articleShow sources
- Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites to RCE Attacks — thehackernews.com — 21.05.2026 06:44
-
Manual patches are provided for Drupal 9.5 and 8.9, which have reached end-of-life, but these releases remain exposed to other previously disclosed vulnerabilities.
First reported: 21.05.2026 06:441 source, 1 articleShow sources
- Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites to RCE Attacks — thehackernews.com — 21.05.2026 06:44