Summary
Drupal has disclosed a highly critical SQL injection vulnerability in its core database abstraction API, tracked as CVE-2026-9082. The flaw specifically affects Drupal sites running on PostgreSQL backends, where unsanitized user-controlled PHP array keys can reach SQL placeholder construction, enabling unauthenticated remote attackers to extract, modify, or delete database contents.
Drupal rates this vulnerability 20 out of 25 on its own risk scale (“Highly Critical”), noting that “all non-public data” is accessible and “all data modifiable or deletable.” Patches are available across six supported Drupal branches, and Drupal has taken the unusual step of issuing two additional patches for end-of-life versions given the severity. A detection proof-of-concept was published the same day as the advisory, and the patch diff was shared publicly within hours.
No in-the-wild exploitation has been confirmed yet, but Drupal’s pre-advisory warning on May 18 explicitly cautioned that exploitation could begin “within hours or days” of disclosure — a timeline consistent with previous Drupalgeddon incidents that saw rapid mass exploitation.
Source
Tenable · Drupal Security Advisory SA-CORE-2026-004
Commentary
If you run Drupal on PostgreSQL, treat this as a five-alarm fire. The Drupalgeddon precedent (CVE-2018-7600 and CVE-2018-7602) showed exactly how fast attackers weaponize Drupal core flaws — automated scanning began within hours, and unpatched sites were compromised en masse. CISA’s KEV catalog already contains four Drupal entries, two with confirmed ransomware use.
The fix itself is almost embarrassingly simple: a single array_values() call to strip attacker-supplied array keys. That such a straightforward sanitization gap existed in core’s database layer is a reminder that even mature, heavily-audited codebases carry decades of technical debt in unexpected places. Patch now. If you’re on MySQL or MariaDB, you’re safe from this specific flaw — but don’t let that delay your update cycle.
