[WID-SEC-2026-1620] Drupal Core (PostgreSQL): Schwachstelle ermöglicht Manipulation von Dateien CVSS Base Score 9.8 (kritisch) CVSS Temporal Score 8.5 (hoch) Remoteangriff ja Datum 20.05.2026 Stand 21.05.2026 Mitigation ja Betroffene Systeme Betriebssystem Sonstiges UNIX Windows Produktbeschreibung Drupal ist ein freies Content-Management-System, basierend auf der Scriptsprache PHP und einer SQL-Datenbank. Über zahlreiche Extensions kann der Funktionsumfang der Core-Installation individuell erweitert werden. Produkte 20.05.2026 Open Source Drupal Core <11.3.10 Open Source Drupal Core <11.2.12 Open Source Drupal Core <11.1.10 Open Source Drupal Core <10.6.9 Open Source Drupal Core <10.5.10 Open Source Drupal Core <10.4.10 Open Source Drupal Core <9.5 Open Source Drupal Core <8.9 Angriff Angriff Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Drupal Core ausnutzen, um eine SQL-Injection durchzuführen, die je nach Datenbankkonfiguration zur Offenlegung von Informationen, zur Erweiterung von Privilegien oder zur potenziellen Ausführung von Remote-Code führen kann. CVE Informationen Versionshistorie Feedback zum Advisory geben
A critical SQL injection vulnerability (CVSS 9.8) in Drupal Core's PostgreSQL driver allows remote, anonymous attackers to manipulate files, potentially leading to information disclosure, privilege escalation, or remote code execution. Affected versions include Drupal Core 11.x prior to 11.3.10, 11.2.x prior to 11.2.12, 11.1.x prior to 11.1.10, 10.6.x prior to 10.6.9, 10.5.x prior to 10.5.10, 10.4.x prior to 10.4.10, and all versions of 9.5.x and 8.9.x. The article confirms mitigations are available but does not specify the exact patched versions or workaround steps.