Drupal has announced the immediate availability of security updates for a vulnerability in Drupal Core that could be exploited by attackers to allow remote code execution, privilege escalation, or information disclosure . The vulnerability exclusively affects websites using PostgreSQL databases and poses a serious threat to thousands of businesses worldwide.

The vulnerability, listed as CVE-2026-9082, carries a CVSS score of 6.5/10.0 and is located in the database abstraction API used in Drupal Core to validate queries and ensure they are sanitized against SQL injection. The fact that the vulnerability is at such a critical point in the system makes immediate notification essential for all administrators.
According to Drupal's official announcement , " a vulnerability in this API allows an attacker to send specially crafted requests, resulting in arbitrary SQL injection databases PostgreSQL for websites using ." This could lead to information disclosure, and in some cases, privilege escalation, remote code execution, or other attacks.
See also: Critical vulnerability in Grist-Core allows RCE attacks
Drupal Core: Vulnerability fixes
The vulnerability can be exploited by anonymous users and only affects websites using PostgreSQL. The following versions are affected:
- Drupal 11.3.10
- Drupal 11.2.12
- Drupal 11.1.10
- Drupal 10.6.9
- Drupal 10.5.10
- Drupal 10.4.10
Importantly, Drupal 7 is not affected by this vulnerability, while releases for supported branches (versions 11.3, 11.2, 10.6, and 10.5) include security updates for Symfony and Twig.
Manual updates have also been released for Drupal 9 and 8, which have reached end-of-life. As Drupal notes: “ Drupal versions 11.1.x, 11.0.x, 10.4.x and earlier are at end-of-life and do not receive security coverage. Both Drupal 8 and Drupal 9 have reached end-of-life.”

Historical context and similar attacks
This vulnerability is part of a long line of critical vulnerabilities in Drupal. Historically, Drupal has suffered from serious SQL injection issues in its core, including the infamous “Drupalgeddon” -era vulnerabilities of 2014. A notable older example is CVE-2014-3704 , which was widely exploited by hackers and became one of Drupal’s most notorious incidents.
See also: Microsoft: Emergency update for vulnerability in ASP.NET Core
The ecosystem has also seen multiple RCE, such as CVE-2019-6340, a highly critical vulnerability that affected certain web services configurations and could lead to arbitrary PHP. Additionally, PostgreSQL has seen recent malicious activity around dump/restore tools, including CVE-2025-8714 and CVE-2025-8715, two high-severity vulnerabilities in pg_dump/pg_restore.
Security experts warn that SQL injection are particularly dangerous because they can expose sensitive content, bypass authorization checks, modify records, and create or escalate administrator-level access. In some cases, they can even become RCEs through database or application login features.
Recommendations for immediate protection
Organizations should take immediate action to protect their systems. First, they should upgrade Drupal Core to the patched version listed in the security advisory, prioritizing all Drupal accessible from the internet, especially those using PostgreSQL.
See also: ChromaDB: Critical vulnerability allows pre-auth RCE via HuggingFace

Additionally, it is critical to take inventory of PostgreSQL-backed Drupal installations, as many organizations update the main sites first and overlook a smaller subset of PostgreSQL.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Finally, it is recommended to review database privileges (to ensure that the Drupal database account has the least privileges), remove unnecessary superuser privileges , and restrict file write capabilities at the database level. Monitoring for abnormal database activity and verifying that backups are up to date are also necessary safeguards.
According to The Hacker News, the severity of this vulnerability makes immediate updating essential for all organizations using Drupal with PostgreSQL databases.
