Drupal Core Flaw Exposes PostgreSQL Sites to RCE via Anonymous SQL Injection

1 min read
Source: The Hacker News
Drupal Core Flaw Exposes PostgreSQL Sites to RCE via Anonymous SQL Injection
Photo: The Hacker News
TL;DR

Drupal released highly critical security updates for Drupal Core to fix CVE-2026-9082, a flaw in the database abstraction API that allows anonymous attackers to perform arbitrary SQL injections on PostgreSQL sites, potentially leading to information disclosure, privilege escalation, or remote code execution (CVSS 6.5). Affected versions include 11.3.10, 11.2.12, 11.1.10, 10.6.9, 10.5.10, and 10.4.10; Drupal 7 is not affected. End-of-life releases are patched on a best-effort basis, and the updates include upstream fixes for Symfony and Twig.

Share this article

Want the full story? Read the original reporting

Read on The Hacker News