ctipilot.ch

Drupal core SA-CORE-2026-004 / CVE-2026-9082 — pre-auth SQL injection on PostgreSQL backends; UPDATE on 2026-05-20 PSA pre-warning

cve · item:drupal-sa-core-2026-004-cve-2026-9082-sql-injection-postgres

Coverage timeline
1
first 2026-05-21 → last 2026-05-21
Briefs
1
1 distinct
Sources cited
14
11 hosts
Sections touched
1
updates
Co-occurring entities
0
no co-occurrence

Story timeline

  1. 2026-05-21CTI Daily Brief — 2026-05-21
    updatesUPDATE on yesterday PSA pre-warning. CVE-2026-9082 assigned; patches released 2026-05-20 (10.4.10 / 10.5.10 / 10.6.9 / 11.1.10 / 11.2.12 / 11.3.10); CWE-89 anon SQLi in core database abstraction API; Drupal risk 20/25 Highly Critical; PostgreSQL only; vendor warned exploits within hours; NCSC-CH carried via Security Hub.

Where this entity is cited

  • updates1

Source distribution

  • drupal.org4 (29%)
  • cert.pl1 (7%)
  • csoonline.com1 (7%)
  • microsoft.com1 (7%)
  • msrc.microsoft.com1 (7%)
  • security-hub.ncsc.admin.ch1 (7%)
  • securityweek.com1 (7%)
  • stepsecurity.io1 (7%)
  • other3 (21%)

External references

NVD · cve.org · CISA KEV

All cited sources (14)

Items in briefs about Drupal core SA-CORE-2026-004 / CVE-2026-9082 — pre-auth SQL injection on PostgreSQL backends; UPDATE on 2026-05-20 PSA pre-warning

No parsed item heading or body matches this entity yet. Items match by exact CVE id (for CVE entities), by lead-segment substring of the title in the item heading or body, or by a distinctive anchor token from the title appearing in the item heading. Coverage that lives inside a broader section (no per-item heading) is captured by the Story timeline above.