Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

CVE-2026-9082: PostgreSQL SQL Injection in Drupal

yeswehack.com | vulnerability | Critical | Actively exploited | CVE-2026-9082 | #active-exploitation | #sql-injection | #postgresql | #poc | #patch-analysis | #cve-2026-9082 | #drupal

Summary

A patch analysis of CVE-2026-9082 (SA-CORE-2026-004): a PostgreSQL-specific SQL injection in Drupal’s entity query subsystem where unsanitised array keys reach SQL, plus PoC paths and the fix.
CVSS
9.8
Published
Collected

original ↗

Related coverage

back