CVE-2018-7600
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Base score: 9.8
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 100%
- Percentile among all scored CVEs: 100
- Score date: 9/29/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
CISA KEV — actively exploited
- Added to catalog: 11/3/2021
- Remediation due date: 5/3/2022
- Known ransomware use: Known
💥 Public exploits
Exploit code or detection templates are publicly available. This is not the same as confirmed active exploitation (KEV), but it raises the risk: patch with priority.
- Metasploit module (reliable, widely available exploit) · Drupal Drupalgeddon 2 Forms API Property Injection
- Published on Exploit-DB · Drupal < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution (Metasploit) (4/17/2018)
- Published on Exploit-DB · Drupal < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution (PoC) (4/13/2018)
- Published on Exploit-DB · Drupal < 7.58 / < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution (4/13/2018)
- Nuclei template (automated mass detection) · Drupal - Remote Code Execution
- Proof of concept on GitHub (unverified) · List of proofs of concept on GitHub
⚠️ GitHub proofs of concept are not verified: some are fake or contain malware. Never run them outside an isolated lab.
🎯 ATT&CK techniques
How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.
- Exploitation
T1190Exploit Public-Facing Applicationinitial access95 % - Primary impact
T1059.003Windows Command Shellexecution90 % - Secondary impact
T1499.004Application or System Exploitationimpact75 % - Secondary impact
T1565.001Stored Data Manipulationimpact70 %
Drupal vulnerable a ejecución remota de código sin autenticación (AV:N, PR:N, UI:N). CVSS crítico (C:H, I:H, A:H) confirma impactos en ejecución, disponibilidad y confidencialidad.
Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.
🛡️ ATT&CK mitigations that cover these techniques
Affected technologies (2)
CWEs
- CWE-20
- CWE-20
References
- http://www.securityfocus.com/bid/103534
- http://www.securitytracker.com/id/1040598
- https://badpackets.net/over-100000-drupal-websites-vulnerable-to-drupalgeddon-2-cve-2018-7600/
- https://blog.appsecco.com/remote-code-execution-with-drupal-core-sa-core-2018-002-95e6ecc0c714
- https://github.com/a2u/CVE-2018-7600
- https://github.com/g0rx/CVE-2018-7600-Drupal-RCE
- https://greysec.net/showthread.php?tid=2912&pid=10561
- https://groups.drupal.org/security/faq-2018-002
- https://lists.debian.org/debian-lts-announce/2018/03/msg00028.html
- https://research.checkpoint.com/uncovering-drupalgeddon-2/
- https://twitter.com/RicterZ/status/979567469726613504
- https://twitter.com/RicterZ/status/984495201354854401
- https://twitter.com/arancaytar/status/979090719003627521
- https://www.debian.org/security/2018/dsa-4156
- https://www.drupal.org/sa-core-2018-002
- https://www.exploit-db.com/exploits/44448/
- https://www.exploit-db.com/exploits/44449/
- https://www.exploit-db.com/exploits/44482/
- https://www.synology.com/support/security/Synology_SA_18_17
- https://www.tenable.com/blog/critical-drupal-core-vulnerability-what-you-need-to-know
- http://www.securityfocus.com/bid/103534
- http://www.securitytracker.com/id/1040598
- https://badpackets.net/over-100000-drupal-websites-vulnerable-to-drupalgeddon-2-cve-2018-7600/
- https://blog.appsecco.com/remote-code-execution-with-drupal-core-sa-core-2018-002-95e6ecc0c714
- https://github.com/a2u/CVE-2018-7600
- https://github.com/g0rx/CVE-2018-7600-Drupal-RCE
- https://greysec.net/showthread.php?tid=2912&pid=10561
- https://groups.drupal.org/security/faq-2018-002
- https://lists.debian.org/debian-lts-announce/2018/03/msg00028.html
- https://research.checkpoint.com/uncovering-drupalgeddon-2/
- https://twitter.com/RicterZ/status/979567469726613504
- https://twitter.com/RicterZ/status/984495201354854401
- https://twitter.com/arancaytar/status/979090719003627521
- https://www.debian.org/security/2018/dsa-4156
- https://www.drupal.org/sa-core-2018-002
- https://www.exploit-db.com/exploits/44448/
- https://www.exploit-db.com/exploits/44449/
- https://www.exploit-db.com/exploits/44482/
- https://www.synology.com/support/security/Synology_SA_18_17
- https://www.tenable.com/blog/critical-drupal-core-vulnerability-what-you-need-to-know
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-7600
Raw JSON (NVD)
Show
{
"id": "CVE-2018-7600",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2018-7600",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "active"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-02-07T12:40:15.444546Z"
}
}
],
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
},
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "mlhess@drupal.org",
"affectedData": [
{
"vendor": "n/a",
"product": "Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1",
"versions": [
{
"status": "affected",
"version": "Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1"
}
]
}
]
}
],
"published": "2018-03-29T07:29:00.260",
"references": [
{
"url": "http://www.securityfocus.com/bid/103534",
"tags": [
"Broken Link",
"Third Party Advisory",
"VDB Entry"
],
"source": "mlhess@drupal.org"
},
{
"url": "http://www.securitytracker.com/id/1040598",
"tags": [
"Broken Link",
"Third Party Advisory",
"VDB Entry"
],
"source": "mlhess@drupal.org"
},
{
"url": "https://badpackets.net/over-100000-drupal-websites-vulnerable-to-drupalgeddon-2-cve-2018-7600/",
"tags": [
"Broken Link",
"Third Party Advisory"
],
"source": "mlhess@drupal.org"
},
{
"url": "https://blog.appsecco.com/remote-code-execution-with-drupal-core-sa-core-2018-002-95e6ecc0c714",
"tags": [
"Third Party Advisory"
],
"source": "mlhess@drupal.org"
},
{
"url": "https://github.com/a2u/CVE-2018-7600",
"tags": [
"Third Party Advisory"
],
"source": "mlhess@drupal.org"
},
{
"url": "https://github.com/g0rx/CVE-2018-7600-Drupal-RCE",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "mlhess@drupal.org"
},
{
"url": "https://greysec.net/showthread.php?tid=2912&pid=10561",
"tags": [
"Broken Link",
"Issue Tracking",
"Third Party Advisory"
],
"source": "mlhess@drupal.org"
},
{
"url": "https://groups.drupal.org/security/faq-2018-002",
"tags": [
"Vendor Advisory"
],
"source": "mlhess@drupal.org"
},
{
"url": "https://lists.debian.org/debian-lts-announce/2018/03/msg00028.html",
"tags": [
"Third Party Advisory"
],
"source": "mlhess@drupal.org"
},
{
"url": "https://research.checkpoint.com/uncovering-drupalgeddon-2/",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "mlhess@drupal.org"
},
{
"url": "https://twitter.com/RicterZ/status/979567469726613504",
"tags": [
"Broken Link",
"Third Party Advisory"
],
"source": "mlhess@drupal.org"
},
{
"url": "https://twitter.com/RicterZ/status/984495201354854401",
"tags": [
"Broken Link",
"Third Party Advisory"
],
"source": "mlhess@drupal.org"
},
{
"url": "https://twitter.com/arancaytar/status/979090719003627521",
"tags": [
"Third Party Advisory"
],
"source": "mlhess@drupal.org"
},
{
"url": "https://www.debian.org/security/2018/dsa-4156",
"tags": [
"Third Party Advisory"
],
"source": "mlhess@drupal.org"
},
{
"url": "https://www.drupal.org/sa-core-2018-002",
"tags": [
"Vendor Advisory"
],
"source": "mlhess@drupal.org"
},
{
"url": "https://www.exploit-db.com/exploits/44448/",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"source": "mlhess@drupal.org"
},
{
"url": "https://www.exploit-db.com/exploits/44449/",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"source": "mlhess@drupal.org"
},
{
"url": "https://www.exploit-db.com/exploits/44482/",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"source": "mlhess@drupal.org"
},
{
"url": "https://www.synology.com/support/security/Synology_SA_18_17",
"tags": [
"Third Party Advisory"
],
"source": "mlhess@drupal.org"
},
{
"url": "https://www.tenable.com/blog/critical-drupal-core-vulnerability-what-you-need-to-know",
"tags": [
"Third Party Advisory"
],
"source": "mlhess@drupal.org"
},
{
"url": "http://www.securityfocus.com/bid/103534",
"tags": [
"Broken Link",
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id/1040598",
"tags": [
"Broken Link",
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://badpackets.net/over-100000-drupal-websites-vulnerable-to-drupalgeddon-2-cve-2018-7600/",
"tags": [
"Broken Link",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://blog.appsecco.com/remote-code-execution-with-drupal-core-sa-core-2018-002-95e6ecc0c714",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/a2u/CVE-2018-7600",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/g0rx/CVE-2018-7600-Drupal-RCE",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://greysec.net/showthread.php?tid=2912&pid=10561",
"tags": [
"Broken Link",
"Issue Tracking",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://groups.drupal.org/security/faq-2018-002",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://lists.debian.org/debian-lts-announce/2018/03/msg00028.html",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://research.checkpoint.com/uncovering-drupalgeddon-2/",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://twitter.com/RicterZ/status/979567469726613504",
"tags": [
"Broken Link",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://twitter.com/RicterZ/status/984495201354854401",
"tags": [
"Broken Link",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://twitter.com/arancaytar/status/979090719003627521",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.debian.org/security/2018/dsa-4156",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.drupal.org/sa-core-2018-002",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.exploit-db.com/exploits/44448/",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.exploit-db.com/exploits/44449/",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.exploit-db.com/exploits/44482/",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.synology.com/support/security/Synology_SA_18_17",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.tenable.com/blog/critical-drupal-core-vulnerability-what-you-need-to-know",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-7600",
"tags": [
"US Government Resource"
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
},
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations."
},
{
"lang": "es",
"value": "Drupal en versiones anteriores a la 7.58, 8.x anteriores a la 8.3.9, 8.4.x anteriores a la 8.4.6 y 8.5.x anteriores a la 8.5.1 permite que los atacantes remotos ejecuten código arbitrario debido a un problema que afecta a múltiples subsistemas con configuraciones de módulos por defecto o comunes."
}
],
"lastModified": "2026-06-17T02:03:25.850",
"cisaActionDue": "2022-05-03",
"cisaExploitAdd": "2021-11-03",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "32918FBA-EEAE-4103-AD2A-0E1914790A2D",
"versionEndIncluding": "7.57"
},
{
"criteria": "cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CB9AA188-842A-4465-833B-066371D5611E",
"versionEndExcluding": "8.3.9",
"versionStartIncluding": "8.0.0"
},
{
"criteria": "cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0C796B60-2568-4E1F-A4CC-710DF21924BD",
"versionEndExcluding": "8.4.6",
"versionStartIncluding": "8.4.0"
},
{
"criteria": "cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FE407010-FFFB-454E-B14A-56AD24B2997C",
"versionEndExcluding": "8.5.1",
"versionStartIncluding": "8.5.0"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "16F59A04-14CF-49E2-9973-645477EA09DA"
},
{
"criteria": "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C11E6FB0-C8C0-4527-9AA0-CB9B316F8F43"
},
{
"criteria": "cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DEECE5FC-CACF-4496-A3E7-164736409252"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "mlhess@drupal.org",
"cisaRequiredAction": "Apply updates per vendor instructions.",
"cisaVulnerabilityName": "Drupal Core Remote Code Execution Vulnerability"
}