AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-9082.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSUnscoredNo severity score in this snapshot.
EXPLOITATION STATUSCISA known exploitedAdded May 22, 2026
RECORD STATUSAwaiting NVD dataModified May 22, 2026

Disclosure summary

Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.

CISA remediation guidance

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

Akamai Blog · RSS-55626384fe1a91aaa0ac03e3b0ea9d852c8

Open original source · Updated May 21, 2026

CVE-2026-9082: Mitigating a Critical SQL Injection Vulnerability in Drupal

CVE mention in publisher metadata; check the original affected versions.

Original records & references

PUBLISHED 2026-05-22T00:00:00-04:00
MODIFIED 2026-05-22T00:00:00-04:00
INGESTED 2026-10-06T11:42:57-04:00