# CVE-2026-9082: Highly Critical Anonymous SQL Injection in Drupal Core PostgreSQL Entity Query Driver (SA-CORE-2026-004)

> CVE-2026-9082 is a highly critical, unauthenticated SQL injection in Drupal core's database abstraction layer that is exploitable only on PostgreSQL-backed sites. Attacker-controlled PHP array KEYS (not values) flow unsanitized from HTTP requests into PostgreSQL PDO placeholder names, letting anonymous users break out of the named-parameter syntax and inject arbitrary SQL via JSON:API filters, the JSON login endpoint, Views exposed filters, and Entity autocomplete. It enables boolean/time-based blind extraction of any database-readable data, including admin (uid=1) password hashes.

- **Published:** 2026-06-10T00:00:00Z
- **Last reviewed:** 2026-06-10T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0750
- **ID:** TL-2026-0750
- **Severity:** CRITICAL (CVSS 6.5)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 17 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-9082

## Description

CVE-2026-9082 (Drupal advisory SA-CORE-2026-004, rated 20/25 'Highly Critical') is a SQL injection vulnerability in Drupal core's Entity Query / database abstraction API. Unlike classic SQLi that targets parameter VALUES, this flaw abuses how PHP associative-array KEYS are converted into PostgreSQL PDO named-placeholder identifiers. PHP's request parser lets an attacker control array keys, and on the PostgreSQL code path those keys are interpolated directly into SQL text before PDO binding occurs.

Root cause: in core/modules/pgsql/src/EntityQuery/Condition.php, the PostgreSQL-specific case-insensitive IN-operator handler iterates over $condition['value'] using the raw array keys to build placeholder names: 'foreach ($condition[''value''] as $key => $value) { $where_id = $where_prefix . $key; $condition[''where''] .= ''LOWER(:'' . $where_id . ''),''; $condition[''where_args''][':'' . $where_id] = $value; }'. The loop assumes sequential numeric keys. If a caller supplies an associative array, $key becomes arbitrary attacker text embedded in the SQL string. Because PostgreSQL/PDO named placeholders only consume identifier characters [a-zA-Z0-9_], any metacharacter in the key (a backtick, single quote, bracket, closing paren, or the || concatenation operator) terminates the placeholder name and everything after it is parsed as literal SQL.

Exploitation paths: (1) JSON:API filter parameters - GET /jsonapi/node/{bundle}?filter[t][condition][value][KEY]=x. Symfony HttpFoundation auto-converts bracketed query parameters into nested PHP arrays, and JSON:API passes the value array straight into the entity query without sanitizing keys. (2) JSON login endpoint - POST /user/login?_format=json with the 'name' field submitted as a JSON object so JsonEncoder decodes it into an associative array, bypassing type validation. (3) Views exposed filters and (4) Entity autocomplete endpoints reach the same vulnerable condition handler. None require authentication or session state.

Data extraction is blind: a true predicate is signaled by an HTTP 500 with PostgreSQL SQLSTATE[22012] (division by zero) when payloads use a 1/(SELECT CASE WHEN ... THEN 0 END) construct, while a false predicate returns HTTP 400 ('unrecognized username or password') or an empty 200 result. A malformed placeholder key surfaces as SQLSTATE[HY093] ('Invalid parameter number'). This permits bit-by-bit boolean-blind and time-based (pg_sleep) extraction of any readable data, including users_field_data and the uid=1 admin password hash, enabling authentication bypass and full site compromise.

The fix resets the array to a sequential integer range with array_values() before the override iterates, applied across core/lib/Drupal/Core/Entity/Query/Sql/Condition.php, core/lib/Drupal/Core/Entity/Query/Sql/ConditionAggregate.php, and core/modules/pgsql/src/EntityQuery/Condition.php. MySQL/MariaDB/SQLite are NOT affected because they take a different code path via Connection::expandArguments(). Drupal 7 is unaffected (no JSON:API in core).

Disclosure and exploitation were rapid: a pre-release PSA on 2026-05-18, advisory + patches on 2026-05-20, a detection/verification PoC the same day, public exploitation tooling and active exploitation within 2-3 days, and CISA KEV addition on 2026-05-22. CVSS is reported as NVD 6.5 (base) versus Drupal's own 20/25 'Highly Critical' rating; researchers note an AI-assisted working exploit was reproduced in ~51 minutes from public information. Imperva reported 15,000+ attack attempts against ~6,000 sites across 65 countries, and CrowdSec observed 68 distinct attacking IPs through 2026-05-25.

## MITRE ATT&CK

- T1595 Active Scanning
- T1592 Gather Victim Host Information
- T1588 Obtain Capabilities
- T1583 Acquire Infrastructure
- T1190 Exploit Public-Facing Application
- T1203 Exploitation for Client Execution
- T1212 Exploitation for Credential Access
- T1552 Unsecured Credentials
- T1082 System Information Discovery
- T1087 Account Discovery
- T1213 Data from Information Repositories
- T1027 Obfuscated Files or Information
- T1567 Exfiltration Over Web Service
- T1078 Valid Accounts
- T1505 Server Software Component
- T1565 Data Manipulation

## Sources

- [SA-CORE-2026-004: Drupal core - Highly critical - SQL injection](https://www.drupal.org/sa-core-2026-004)
- [CVE-2026-9082: Mitigating a Critical SQL Injection in Drupal](https://www.akamai.com/blog/security-research/cve-2026-9082-mitigating-critical-sql-injection-drupal)
- [Keys to the Kingdom: Anonymous SQL Injection in Drupal Core (CVE-2026-9082)](https://slcyber.io/research-center/keys-to-the-kingdom-anonymous-sql-injection-in-drupal-core-cve-2026-9082/)
- [CVE-2026-9082: Highly Critical SQL Injection Vulnerability in Drupal Core (SA-CORE-2026-004)](https://www.tenable.com/blog/cve-2026-9082-highly-critical-sql-injection-vulnerability-in-drupal-core-sa-core-2026-004)
- [CVE-2026-9082-Drupal-PoC (ethical detection/extraction PoC)](https://github.com/7h30th3r0n3/CVE-2026-9082-Drupal-PoC)
- [CVE-2026-9082: Critical Drupal Core SQLi Flaw - Analysis](https://socprime.com/blog/cve-2026-9082-analysis/)
- [CVE-2026-9082: Drupal JSON:API SQL Injection Under Active Exploitation](https://www.crowdsec.net/vulntracking-report/cve-2026-9082-drupal-jsonapi-sql-injection)
- [CVE-2026-9082 Drupal Core PostgreSQL SQL Injection Overview and Takeaways](https://www.netspi.com/blog/executive-blog/critical-vulnerability/cve-2026-9082-drupal-core-postgresql-sql-injection-overview-and-takeaways/)
- [CVE-2026-9082: PostgreSQL-specific SQL injection in Drupal](https://www.yeswehack.com/news/cve-2026-9082-postgresql-drupal)
- [Drupal Core SQL Injection Vulnerability Added to CISA KEV (CVE-2026-9082)](https://threatprotect.qualys.com/2026/05/25/drupal-core-sql-injection-vulnerability-added-to-cisa-kev-cve-2026-9082/)
- [CISA orders feds to patch actively exploited Drupal vulnerability](https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-drupal-vulnerability/)
- [CISA Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog)
- [CVE-2026-9082: exploited Drupal PostgreSQL SQL injection reaches KEV](https://corgea.com/research/cve-2026-9082-drupal-postgresql-sql-injection-kev)
- [Miggo Study: AI-Generated Exploit for Drupal CVE-2026-9082 Within 51 Minutes](https://www.thedroptimes.com/70116/miggo-ai-exploit-drupal-cve-2026-9082)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0750
