Drupal Product Security Update Advisory (CVE-2026-9082)
Overview
A security update has been released to address a vulnerability in the Drupal product. the vulnerability is CVE-2026-9082, a SQL injection (SQL injection, an attack that maliciously manipulates database queries) vulnerability in Drupal core.
Affected
the following Drupal core versions are affected
- 8.9.0 and above but below 10.4.10.
- 10.5.0 and above but below 10.5.10.
- 10.6.0 and above but below 10.6.9.
- 11.0.0 or later but less than 11.1.10.
- 11.2.0 or higher but less than 11.2.12.
- 11.3.0 or higher but less than 11.3.10.
Workaround
the vulnerability has been patched in the latest update. you can update to the following versions by following the instructions on the reference site.
- Drupal core 10.4.10.
- Drupal core 10.5.10.
- Drupal core 10.6.9.
- Drupal core 11.1.10.
- Drupal core 11.2.12.
- Drupal core 11.3.10.
Note
- Drupal core – Highly critical – SQL injection – SA-CORE-2026-004.
- available at https://www.drupal.org/sa-core-2026-004.