« Volver al listado

CVE-2026-6366

Estado: AnalizadaMedia (6.6)—

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.

This issue affects Drupal core: from 8.0.0 before 10.5.9, from 10.6.0 before 10.6.7, from 11.0.0 before 11.2.11, from 11.3.0 before 11.3.7.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-6366",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-6366",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-04-30T00:00:00+00:00"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.6,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 0.7
      }
    ]
  },
  "affected": [
    {
      "source": "mlhess@drupal.org",
      "affectedData": [
        {
          "repo": "https://git.drupalcode.org/project/drupal",
          "vendor": "Drupal",
          "product": "Drupal core",
          "versions": [
            {
              "status": "affected",
              "version": "8.0.0",
              "lessThan": "10.5.9",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "10.6.0",
              "lessThan": "10.6.7",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "11.0.0",
              "lessThan": "11.2.11",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "11.3.0",
              "lessThan": "11.3.7",
              "versionType": "semver"
            }
          ],
          "collectionURL": "https://www.drupal.org/project/drupal",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-05-19T23:16:58.233",
  "references": [
    {
      "url": "https://www.drupal.org/sa-core-2026-002",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "mlhess@drupal.org"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "mlhess@drupal.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-915"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.\n\nThis issue affects Drupal core: from 8.0.0 before 10.5.9, from 10.6.0 before 10.6.7, from 11.0.0 before 11.2.11, from 11.3.0 before 11.3.7."
    },
    {
      "lang": "es",
      "value": "Modificación controlada de forma inadecuada de atributos de objeto determinados dinámicamente vulnerabilidad en el núcleo de Drupal Drupal permite la inyección de objetos.\n\nEste problema afecta al núcleo de Drupal: desde 8.0.0 antes de 10.5.9, desde 10.6.0 antes de 10.6.7, desde 11.0.0 antes de 11.2.11, desde 11.3.0 antes de 11.3.7."
    }
  ],
  "lastModified": "2026-07-24T08:10:00.150",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8326F74A-316D-4017-9A1A-8ED8F093363B",
              "versionEndExcluding": "10.5.9",
              "versionStartIncluding": "8.0.0"
            },
            {
              "criteria": "cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C85BA74C-BFE9-4547-8BB0-091E9FBB7BF0",
              "versionEndExcluding": "10.6.7",
              "versionStartIncluding": "10.6.0"
            },
            {
              "criteria": "cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2A5FFDBD-3AB7-48A2-BFF5-B35F78AFDB76",
              "versionEndExcluding": "11.2.11",
              "versionStartIncluding": "11.0.0"
            },
            {
              "criteria": "cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E2562EDF-52F1-4415-A686-0CCED9DB3651",
              "versionEndExcluding": "11.3.7",
              "versionStartIncluding": "11.3.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "mlhess@drupal.org"
}