CVE-2026-9082 Drupal Core PostgreSQL SQL Injection Overview and Takeaways
netspi.com | vulnerability | CVE-2026-9082 | #rce | #postgresql | #sqli | #cms | #cve-2026-9082 | #drupal | #patch-now
Summary
CVE-2026-9082 (CVSS 9.8) lets unauthenticated attackers run arbitrary SQL against Drupal Core on PostgreSQL via crafted JSON:API queries, risking database compromise or RCE; upgrade immediately.
- CVE
- CVE-2026-9082
- Published
- Collected
Skip to content