# CVE-2026-9082: Drupal - SQLi

> Live exploitation tracking for CVE-2026-9082 by the CrowdSec Live Exploit Tracker, built from real-world attack data crowdsourced from CrowdSec's global network.

Page: https://tracker.crowdsec.net/cves/CVE-2026-9082

## Key facts

- **Exploitation phase:** Active Exploitation. The vulnerability is actively exploited at scale across the internet, often via automated tools and large attack campaigns.
- **CVSS score:** 6.5
- **Public exploit available:** Yes
- **Affected products:** Drupal core
- **Weaknesses:** CWE-89 (Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'))
- **Tags:** php, cms

## Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal core allows SQL Injection via the JSON:API filter parameter keys.

## CrowdSec analysis

[CVE-2026-9082](https://euvd.enisa.europa.eu/vulnerability/CVE-2026-9082) is a SQL injection vulnerability in Drupal core's JSON:API module. Attackers can inject SQL through specially crafted filter parameter keys on `/jsonapi/` endpoints, potentially leading to unauthorized database reads or writes. The flaw affects multiple Drupal core release lines and is fixed in 10.4.10, 10.5.10, 10.6.9, 11.1.10, 11.2.12, and 11.3.10.

CrowdSec has been tracking this vulnerability and its exploits since 22nd of May 2026.

According to CrowdSec data, while opportunistic exploitation dominates, a portion of threat actors trying to exploit CVE-2026-9082 apply basic targeting methods such as port or service detection. This indicates emerging patterns of selective targeting.
In addition, according to the CrowdSec network, attack volume against CVE-2026-9082 has dipped slightly compared to the previous week. Although still commonly targeted, the decline suggests a cooling-off period. Long-term relevance remains, but attention is waning.

Attackers send requests to `/jsonapi/` endpoints with filter parameter keys containing SQL metacharacters such as `||` or backticks (e.g. `?filter[a||SLEEP(5)--]=1`), causing the JSON:API filter resolver to concatenate the malicious key into the underlying SQL query.

## Timeline

- 2026-05-20: CVE Published. CVE-2026-9082 is published to NVD.
- 2026-05-22: Rule Released. CrowdSec releases a rule to detect CVE-2026-9082 exploitation attempts against the CrowdSec Network.
- 2026-05-22: CISA KEV. CVE-2026-9082 is added to the Known Exploited Vulnerabilities catalog by CISA.
- 2026-05-23: CrowdSec First Seen. CrowdSec observes in-the-wild exploitation of CVE-2026-9082 for the first time.
- 2026-05-27: CISA Remediation Deadline. Expiration of the CISA remediation deadline as described in [BOD 22-01](https://www.cisa.gov/news-events/directives/bod-22-01-reducing-significant-risk-known-exploited-vulnerabilities).

## References

- https://www.drupal.org/sa-core-2026-004

## Live exploitation data

The [Live Exploit Tracker page](https://tracker.crowdsec.net/cves/CVE-2026-9082) follows observed exploitation activity for CVE-2026-9082. [Request an API key](https://tracker.crowdsec.net/request-api-key) for full access to its exploitation timeline, attacking IP addresses and blocklists.
