CVE-2026-9082CISA KEV: Actively Exploited

Drupal Core SQL Injection Vulnerability

Published May 22, 2026·Updated May 22, 2026

Description

Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.

Public Exploits & PoCs11 found

[POC] CVE-2026-9082 — CVE-2026-9082-Mass_Scanner

Mass Scanner For Drupal Exploit CVE-2026-9082

1

[POC] CVE-2026-9082 — cve-2026-9082

cve poc

[POC] CVE-2026-9082 — CVE-2026-9082

CVE-2026-9082 | SA-CORE-2026-004

[POC] CVE-2026-9082 — CVE-2026-9082

Drupal Core PostgreSQL SQLi to RCE via /user/login (CVE-2026-9082 / SA-CORE-2026-004)

[POC] CVE-2026-9082 — CVE-2026-9082

Passive checker for CVE-2026-9082 / SA-CORE-2026-004 (Drupal core SQL injection, PostgreSQL)

[POC] CVE-2026-9082 — drupal-cve-2026-9082-checker

Drupal CVE-2026-9082 Blind SQL Injection Checker (Single & Bulk)

[POC] CVE-2026-9082 — CVE-2026-9082

Drupal PostgreSQL SQLi Scanner - Unauthenticated SQL Injection in Drupal Core via JSON:API (CISA KEV May 2026)

[POC] CVE-2026-9082 — CVE-2026-9082

PoC for CVE-2026-9082 (Drupal SA-CORE-2026-004) Drupal Core SQLi

[POC] CVE-2026-9082 — CVE-2026-9082

CVE-2026-9082

[POC] CVE-2026-9082 — CVE-2026-9082-Drupal-PoC

Drupal Core PostgreSQL SQL Injection PoC - CVE-2026-9082. Ethical PoC for the Drupal vulnerability allowing anonymous SQL injection through the JSON:API module on PostgreSQL-backed sites.

PoC: cve-2026-9082-drupal

drupal-postgresql-rce

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free