CVE-2026-9082: PostgreSQL SQL Injection in Drupal
yeswehack.com | vulnerability | Critical | Actively exploited | CVE-2026-9082 | #active-exploitation | #sql-injection | #postgresql | #poc | #patch-analysis | #cve-2026-9082 | #drupal
Summary
A patch analysis of CVE-2026-9082 (SA-CORE-2026-004): a PostgreSQL-specific SQL injection in Drupal’s entity query subsystem where unsanitised array keys reach SQL, plus PoC paths and the fix.
- CVSS
- 9.8
- Published
- Collected
Skip to content