CrowdSecLive Exploit Tracker
Active ExploitationCVE-2026-9082Public Exploit

Drupal - SQLi (CVE-2026-9082)

PublishedMay 20, 2026
First SeenMay 23, 2026
Last Seen
Reported
CVSS6.5
phpcms

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal core allows SQL Injection via the JSON:API filter parameter keys.

psychologyCrowdSec Analysis

CVE-2026-9082 is a SQL injection vulnerability in Drupal core's JSON:API module. Attackers can inject SQL through specially crafted filter parameter keys on /jsonapi/ endpoints, potentially leading to unauthorized database reads or writes. The flaw affects multiple Drupal core release lines and is fixed in 10.4.10, 10.5.10, 10.6.9, 11.1.10, 11.2.12, and 11.3.10.

CrowdSec has been tracking this vulnerability and its exploits since 22nd of May 2026.

According to CrowdSec data, while opportunistic exploitation dominates, a portion of threat actors trying to exploit CVE-2026-9082 apply basic targeting methods such as port or service detection. This indicates emerging patterns of selective targeting. In addition, according to the CrowdSec network, attack volume against CVE-2026-9082 has dipped slightly compared to the previous week. Although still commonly targeted, the decline suggests a cooling-off period. Long-term relevance remains, but attention is waning.

Attackers send requests to /jsonapi/ endpoints with filter parameter keys containing SQL metacharacters such as || or backticks (e.g. ?filter[a||SLEEP(5)--]=1), causing the JSON:API filter resolver to concatenate the malicious key into the underlying SQL query.

lock

Full Intelligence Available

Connect your API key to access CrowdSec scores, exploit timelines, and attacker IPs.

EventDate
CVE Published2026-05-20
Rule Released2026-05-22
CISA KEV2026-05-22
CrowdSec First Seen2026-05-23
CISA Remediation Deadline2026-05-27

Remediation & Protection

lock to download blocklists, subscribe to firewalls, and access IP intelligence.