CVE-2026-9082

MEDIUM KEV NUCLEI LAB

Drupal core - Highly critical - SQL injection - SA-CORE-2026-004

Title source: cna
STIX 2.1

Exploitation Summary

CVE-2026-9082 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added May 22, 2026. EIP tracks 7 public exploits from researchers including N45HT, ridhinva, ywh-jfellus. A Nuclei detection template is also available.

AI-analyzed exploit summary The repository claims to be a checker for a Drupal Blind SQL Injection vulnerability but contains no actual code or technical details. It appears to be a placeholder or lure.

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.1.10, from 11.2.0 before 11.2.12, from 11.3.0 before 11.3.10.

Exploits (7)

github SUSPICIOUS
by N45HT · poc
https://github.com/N45HT/drupal-cve-2026-9082-checker

The repository claims to be a checker for a Drupal Blind SQL Injection vulnerability but contains no actual code or technical details. It appears to be a placeholder or lure.

Classification
Suspicious 90%
Attack Type
Sqli
Complexity
Theoretical
Reliability
Theoretical
Target: Drupal (version unspecified)
No auth needed
Prerequisites: none specified
devstral-2 · analyzed May 24, 2026 Full analysis →
github WORKING POC
by ridhinva · pythonpoc
https://github.com/ridhinva/CVE-2026-9082

This repository contains a functional exploit for CVE-2026-9082, a critical SQL injection vulnerability in Drupal Core (8.0-11.3.9) with PostgreSQL backend. The exploit leverages JSON:API filter array key injection via PDO placeholder name abuse to achieve unauthenticated SQLi, enabling data exfiltration, privilege escalation, and potential RCE.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Drupal Core 8.0-11.3.9 with PostgreSQL backend
No auth needed
Prerequisites: Drupal site with JSON:API enabled · PostgreSQL backend
devstral-2 · analyzed May 23, 2026 Full analysis →
github WORKING POC
by ywh-jfellus · pythonpoc
https://github.com/ywh-jfellus/CVE-2026-9082

This repository contains a functional Python-based PoC for CVE-2026-9082, a SQL injection vulnerability in Drupal core's PostgreSQL entity-query condition translator. The exploit leverages the JSON:API layer to inject malformed SQL conditions, causing a 500 error if the target is vulnerable.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Drupal core (10.4.9 and earlier, patched in 11.2.12)
No auth needed
Prerequisites: Drupal with PostgreSQL backend · JSON:API enabled
devstral-2 · analyzed May 22, 2026 Full analysis →
github WORKING POC
by 7h30th3r0n3 · pythonpoc
https://github.com/7h30th3r0n3/CVE-2026-9082-Drupal-PoC

This repository contains a functional Python-based exploit for CVE-2026-9082, a PostgreSQL SQL injection vulnerability in Drupal Core. The exploit leverages unsanitized array keys in JSON:API filter parameters to inject arbitrary SQL, with support for time-based and boolean-based detection, as well as data extraction.

Classification
Working Poc 100%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Drupal Core 8.0 - 11.3.9 (PostgreSQL backend)
No auth needed
Prerequisites: Drupal with PostgreSQL backend · JSON:API module enabled
devstral-2 · analyzed May 21, 2026 Full analysis →
github SCANNER
by 0xBlackash · pythonpoc
https://github.com/0xBlackash/CVE-2026-9082

The repository contains a Python script that checks for the presence of Drupal and tests for potential vulnerability to CVE-2026-9082 by probing specific endpoints. It does not include exploit code but provides a detection mechanism.

Classification
Scanner 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: Drupal Core (PostgreSQL backend)
No auth needed
Prerequisites: Drupal installation with PostgreSQL backend · Accessible autocomplete endpoints
devstral-2 · analyzed May 21, 2026 Full analysis →
github WRITEUP
by lysophavin18 · poc
https://github.com/lysophavin18/cve-2026-9082

This repository provides a detailed technical analysis of CVE-2026-9082, a SQL injection vulnerability in Drupal Core's database abstraction API affecting PostgreSQL backends. It includes root cause analysis, exploitation techniques, mitigation steps, and detection signals.

Classification
Writeup 100%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Drupal Core (8.9.x-11.3.x) with PostgreSQL backend
No auth needed
Prerequisites: PostgreSQL backend · Exposed Drupal endpoints passing user input to DB queries
devstral-2 · analyzed May 21, 2026 Full analysis →
github WORKING POC
by HORKimhab · pythonpoc
https://github.com/HORKimhab/CVE-2026-9082

This repository contains a functional exploit PoC for CVE-2026-9082, a SQL injection vulnerability in Drupal 8.0-11.3.9 via attacker-controlled array keys in JSON:API filter values. The PoC includes a Python script to detect and validate the vulnerability, along with detailed analysis and a lab setup for testing.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Drupal 8.0-11.3.9
No auth needed
Prerequisites: Drupal with JSON:API enabled · PostgreSQL backend · case-insensitive field in EntityQuery
devstral-2 · analyzed May 21, 2026 Full analysis →

Nuclei Templates (1)

Drupal Core - Anonymous SQL Injection via PostgreSQL Entity Query
CRITICALVERIFIEDby slcyber,DhiyaneshDk
Shodan: http.component:"Drupal"
FOFA: app="drupal"

References (1)

Core 1

Scores

CVSS v3 6.5
EPSS 0.1257
EPSS Percentile 94.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact total

Lab Environment

COMMUNITY
Community Lab
docker pull drupal:11.3.9-php8.4-apache
docker pull drupal:11.3.9
docker pull drupal:10.4.9-php8.3-apache
+3 more repos

Details

CISA KEV 2026-05-22
VulnCheck KEV 2026-05-22
ENISA EUVD EUVD-2026-31153
CWE
CWE-89
Status published
Products (6)
Drupal/Drupal core 10.5.0 - 10.5.10
Drupal/Drupal core 10.6.0 - 10.6.9
Drupal/Drupal core 11.0.0 - 11.1.10
Drupal/Drupal core 11.2.0 - 11.2.12
Drupal/Drupal core 11.3.0 - 11.3.10
Drupal/Drupal core 8.9.0 - 10.4.10
Published May 20, 2026
KEV Added May 22, 2026
Tracked Since May 21, 2026