« Volver al listado

CVE-2026-9082

Estado: AnalizadaCrítica (9.8)⚠ Explotación activa

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection.

This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.1.10, from 11.2.0 before 11.2.12, from 11.3.0 before 11.3.10.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

CISA KEV — explotada activamente

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

SQL injection (CWE-89) en Drupal accesible remotamente sin autenticación (AV:N/PR:N) permite lectura y manipulación de datos; impacto crítico (C:H/I:H/A:H) sugiere potencial ejecución remota si el backend ejecuta comandos.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-9082",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-9082",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "active"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-05-20T00:00:00+00:00"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "mlhess@drupal.org",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "mlhess@drupal.org",
      "affectedData": [
        {
          "repo": "https://git.drupalcode.org/project/drupal",
          "vendor": "Drupal",
          "product": "Drupal core",
          "versions": [
            {
              "status": "affected",
              "version": "8.9.0",
              "lessThan": "10.4.10",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "10.5.0",
              "lessThan": "10.5.10",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "10.6.0",
              "lessThan": "10.6.9",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "11.0.0",
              "lessThan": "11.1.10",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "11.2.0",
              "lessThan": "11.2.12",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "11.3.0",
              "lessThan": "11.3.10",
              "versionType": "semver"
            }
          ],
          "collectionURL": "https://www.drupal.org/project/drupal",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-05-20T20:16:41.230",
  "references": [
    {
      "url": "https://www.drupal.org/sa-core-2026-004",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "mlhess@drupal.org"
    },
    {
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-9082",
      "tags": [
        "US Government Resource"
      ],
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "mlhess@drupal.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-89"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection.\n\nThis issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.1.10, from 11.2.0 before 11.2.12, from 11.3.0 before 11.3.10."
    },
    {
      "lang": "es",
      "value": "Neutralización Incorrecta de Elementos Especiales utilizados en un Comando SQL ('inyección SQL') vulnerabilidad en Drupal Drupal core permite inyección SQL.\n\nEste problema afecta a Drupal core: desde 8.9.0 antes de 10.4.10, desde 10.5.0 antes de 10.5.10, desde 10.6.0 antes de 10.6.9, desde 11.0.0 antes de 11.1.10, desde 11.2.0 antes de 11.2.12, desde 11.3.0 antes de 11.3.10."
    }
  ],
  "lastModified": "2026-07-23T16:10:00.137",
  "cisaActionDue": "2026-05-27",
  "cisaExploitAdd": "2026-05-22",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D913070F-48D6-4282-8F54-72F40C57EFE9",
              "versionEndExcluding": "10.4.10",
              "versionStartIncluding": "8.9.0"
            },
            {
              "criteria": "cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "358B0EE2-C620-4B3C-ACF3-A0537BF3DCD9",
              "versionEndExcluding": "10.5.10",
              "versionStartIncluding": "10.5.0"
            },
            {
              "criteria": "cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "27F0A477-45CF-4670-A40B-C45EF45DDFD8",
              "versionEndExcluding": "10.6.9",
              "versionStartIncluding": "10.6.0"
            },
            {
              "criteria": "cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2CA9EE15-B47E-416A-9486-8A3CA815EF22",
              "versionEndExcluding": "11.1.10",
              "versionStartIncluding": "11.0.0"
            },
            {
              "criteria": "cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F34F68CB-E0D0-4F30-9B8C-7A51BF285F26",
              "versionEndExcluding": "11.2.12",
              "versionStartIncluding": "11.2.0"
            },
            {
              "criteria": "cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C878524F-B5D0-4894-81BD-6E17AFB30A4A",
              "versionEndExcluding": "11.3.10",
              "versionStartIncluding": "11.3.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "mlhess@drupal.org",
  "cisaRequiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "cisaVulnerabilityName": "Drupal Core SQL Injection Vulnerability"
}