Threat reportVulnerabilityTL-2026-0750
CVE-2026-9082: Highly Critical Anonymous SQL Injection in Drupal Core PostgreSQL Entity Query Driver (SA-CORE-2026-004)
CVE-2026-9082 (TL-2026-0750), also tracked as SA-CORE-2026-004, is a critical-severity software vulnerability scored CVSS 6.5, first published 2026-06-10. It has no confirmed attribution, affects Drupal Drupal core (PostgreSQL backend only), references 1 CVE (CVE-2026-9082), maps to 16 MITRE ATT&CK techniques (T1027, T1078, T1082), and is covered by 9 detection rules and 17 indicators of compromise.
- CVSS
- 6.5/10Critical
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 16MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 17Indicators of compromise
Key facts for TL-2026-0750
- Threat ID
- TL-2026-0750
- Also known as
- SA-CORE-2026-004, Keys to the Kingdom
- Severity
- CRITICAL
- CVSS
- 6.5
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- government, financial, gaming, technology, media, education, healthcare, ecommerce
- Target regions
- North America, Europe, Asia, Global
- Detection rules
- 9
- Indicators of compromise
- 17
Malware and tooling in CVE-2026-9082
Malware and tooling: CVE-2026-9082.py (7h30th3r0n3 Drupal PoC)
How CVE-2026-9082 works
CVE-2026-9082 is a highly critical, unauthenticated SQL injection in Drupal core's database abstraction layer that is exploitable only on PostgreSQL-backed sites. Attacker-controlled PHP array KEYS (not values) flow unsanitized from HTTP requests into PostgreSQL PDO placeholder names, letting anonymous users break out of the named-parameter syntax and inject arbitrary SQL via JSON:API filters, the JSON login endpoint, Views exposed filters, and Entity autocomplete. It enables boolean/time-based blind extraction of any database-readable data, including admin (uid=1) password hashes.
CVE-2026-9082 (Drupal advisory SA-CORE-2026-004, rated 20/25 'Highly Critical') is a SQL injection vulnerability in Drupal core's Entity Query / database abstraction API. Unlike classic SQLi that targets parameter VALUES, this flaw abuses how PHP associative-array KEYS are converted into PostgreSQL PDO named-placeholder identifiers. PHP's request parser lets an attacker control array keys, and on the PostgreSQL code path those keys are interpolated directly into SQL text before PDO binding occurs.
Root cause: in core/modules/pgsql/src/EntityQuery/Condition.php, the PostgreSQL-specific case-insensitive IN-operator handler iterates over $condition['value'] using the raw array keys to build placeholder names: 'foreach ($condition[''value''] as $key => $value) { $where_id = $where_prefix . $key; $condition[''where''] .= ''LOWER(:'' . $where_id . ''),''; $condition[''where_args''][':'' . $where_id] = $value; }'. The loop assumes sequential numeric keys. If a caller supplies an associative array, $key becomes arbitrary attacker text embedded in the SQL string. Because PostgreSQL/PDO named placeholders only consume identifier characters [a-zA-Z0-9_], any metacharacter in the key (a backtick, single quote, bracket, closing paren, or the || concatenation operator) terminates the placeholder name and everything after it is parsed as literal SQL.
Exploitation paths: (1) JSON:API filter parameters - GET /jsonapi/node/{bundle}?filter[t][condition][value][KEY]=x. Symfony HttpFoundation auto-converts bracketed query parameters into nested PHP arrays, and JSON:API passes the value array straight into the entity query without sanitizing keys. (2) JSON login endpoint - POST /user/login?_format=json with the 'name' field submitted as a JSON object so JsonEncoder decodes it into an associative array, bypassing type validation. (3) Views exposed filters and (4) Entity autocomplete endpoints reach the same vulnerable condition handler. None require authentication or session state.
Data extraction is blind: a true predicate is signaled by an HTTP 500 with PostgreSQL SQLSTATE[22012] (division by zero) when payloads use a 1/(SELECT CASE WHEN ... THEN 0 END) construct, while a false predicate returns HTTP 400 ('unrecognized username or password') or an empty 200 result. A malformed placeholder key surfaces as SQLSTATE[HY093] ('Invalid parameter number'). This permits bit-by-bit boolean-blind and time-based (pg_sleep) extraction of any readable data, including users_field_data and the uid=1 admin password hash, enabling authentication bypass and full site compromise.
The fix resets the array to a sequential integer range with array_values() before the override iterates, applied across core/lib/Drupal/Core/Entity/Query/Sql/Condition.php, core/lib/Drupal/Core/Entity/Query/Sql/ConditionAggregate.php, and core/modules/pgsql/src/EntityQuery/Condition.php. MySQL/MariaDB/SQLite are NOT affected because they take a different code path via Connection::expandArguments(). Drupal 7 is unaffected (no JSON:API in core).
Disclosure and exploitation were rapid: a pre-release PSA on 2026-05-18, advisory + patches on 2026-05-20, a detection/verification PoC the same day, public exploitation tooling and active exploitation within 2-3 days, and CISA KEV addition on 2026-05-22. CVSS is reported as NVD 6.5 (base) versus Drupal's own 20/25 'Highly Critical' rating; researchers note an AI-assisted working exploit was reproduced in ~51 minutes from public information. Imperva reported 15,000+ attack attempts against ~6,000 sites across 65 countries, and CrowdSec observed 68 distinct attacking IPs through 2026-05-25.
MITRE ATT&CK techniques used in TL-2026-0750
Defense Evasion
T1027 Obfuscated Files or Information
Initial Access
T1078 Valid Accounts; T1190 Exploit Public-Facing Application
Discovery
T1082 System Information Discovery; T1087 Account Discovery
Execution
T1203 Exploitation for Client Execution
Credential Access
T1212 Exploitation for Credential Access; T1552 Unsecured Credentials
Collection
T1213 Data from Information Repositories
Persistence
T1505 Server Software Component
Impact
Exfiltration
T1567 Exfiltration Over Web Service
Resource Development
T1583 Acquire Infrastructure; T1588 Obtain Capabilities
Reconnaissance
Affected products and versions in CVE-2026-9082
- Drupal — Drupal core (PostgreSQL backend only)
Vulnerable versions: 8.9.x and earlier 8.x; 9.0.x-9.5.x; 10.4.0-10.4.9; 10.5.0-10.5.9; 10.6.0-10.6.8; 11.0.0-11.1.9; 11.2.0-11.2.11; 11.3.0-11.3.9
Fixed in: 10.4.10; 10.5.10; 10.6.9; 11.1.10; 11.2.12; 11.3.10
Remediation for CVE-2026-9082
Patches
- Drupal core 11.3.10
- Drupal core 11.2.12
- Drupal core 11.1.10 (exceptional EOL release)
- Drupal core 10.6.9
- Drupal core 10.5.10
- Drupal core 10.4.10 (exceptional EOL release)
- Best-effort manual patches for EOL Drupal 9.5 and 8.9
Immediate actions
- Upgrade Drupal core to the patched release for your branch: 11.3.10, 11.2.12, 11.1.10, 10.6.9, 10.5.10, or 10.4.10
- If immediate upgrade is impossible, apply the official SA-CORE-2026-004 patch (array_values() reset in the Entity Query Condition handlers)
- Disable or restrict the JSON:API module if not required; lock down /jsonapi/ and /user/login?_format=json at the WAF/reverse proxy
- Block requests whose filter[*][condition][value] keys contain SQL metacharacters (backtick, single quote, parentheses, comment sequences, ||, OR/SELECT, pg_sleep)
Workarounds
- Disable the JSON:API module
- Restrict anonymous access to JSON:API, Views exposed filters and Entity autocomplete endpoints
- Migrate the site database off PostgreSQL is NOT a recommended mitigation; patching is required
Longer-term hardening
- Deploy WAF SQLi rule coverage (e.g. Akamai App & API Protector rules 950902, 959073, 981255, 3000101)
- Hunt PostgreSQL/PHP logs for SQLSTATE[22012] and SQLSTATE[HY093] errors originating from JSON:API and login endpoints
- Audit for end-of-life Drupal 8.9/9.5 installs and migrate to a supported, patched branch
- Rotate all credentials and force password resets if blind extraction or admin-hash access is suspected
CVEs associated with CVE-2026-9082
Weaknesses (CWE) in CVE-2026-9082
Timeline of CVE-2026-9082
- Drupal Security Team issues a pre-release Public Service Announcement (PSA) warning of an upcoming highly critical core release.
- A detection/verification proof-of-concept for CVE-2026-9082 is published.
- Drupal publishes advisory SA-CORE-2026-004 (CVE-2026-9082), rated 20/25 'Highly Critical', along with patched releases 11.3.10, 11.2.12, 11.1.10, 10.6.9, 10.5.10 and 10.4.10. Credited reporter: Michael Maturi; JSON login variant analysis contributed by Animesh Acharya (Tanto Security).
- CrowdSec observes early probing attempts against /jsonapi/ endpoints.
- Akamai and Searchlight Cyber publish technical analyses ('Keys to the Kingdom') detailing the PHP array-key to PDO placeholder injection and blind extraction primitive.
- CISA adds CVE-2026-9082 to the Known Exploited Vulnerabilities (KEV) catalog and orders federal agencies to patch.
- Exploit attempts are detected in the wild; risk score updated to reflect active exploitation.
- CrowdSec observes confirmed exploitation across its network; BleepingComputer reports CISA's patch order.
- Miggo study reports an AI-assisted working exploit reproduced from public information in approximately 51 minutes.
- CrowdSec reports 68 distinct attacking IPs through May 25; Imperva reports 15,000+ attack attempts against ~6,000 sites across 65 countries, concentrated on gaming and financial-services sites.
Sources cited for CVE-2026-9082
- SA-CORE-2026-004: Drupal core - Highly critical - SQL injection
- CVE-2026-9082: Mitigating a Critical SQL Injection in Drupal
- Keys to the Kingdom: Anonymous SQL Injection in Drupal Core (CVE-2026-9082)
- CVE-2026-9082: Highly Critical SQL Injection Vulnerability in Drupal Core (SA-CORE-2026-004)
- CVE-2026-9082-Drupal-PoC (ethical detection/extraction PoC)
- CVE-2026-9082: Critical Drupal Core SQLi Flaw - Analysis
- CVE-2026-9082: Drupal JSON:API SQL Injection Under Active Exploitation
- CVE-2026-9082 Drupal Core PostgreSQL SQL Injection Overview and Takeaways
- CVE-2026-9082: PostgreSQL-specific SQL injection in Drupal
- Drupal Core SQL Injection Vulnerability Added to CISA KEV (CVE-2026-9082)
- CISA orders feds to patch actively exploited Drupal vulnerability
- CISA Known Exploited Vulnerabilities Catalog
- CVE-2026-9082: exploited Drupal PostgreSQL SQL injection reaches KEV
- Miggo Study: AI-Generated Exploit for Drupal CVE-2026-9082 Within 51 Minutes
Detection coverage for TL-2026-0750
As of 2026-06-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0750 across Splunk SPL, Microsoft KQL and Sigma, covering 17 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.