CVE-2026-9082 – Drupal Core SQL Injection

CVE-2026-9082 – Drupal Core SQL Injection

CVE-2026-9082 is a highly critical SQL injection vulnerability in Drupal core's database abstraction API, specifically in the PostgreSQL EntityQuery condition handler. An unauthenticated, remote attacker can exploit this vulnerability by…