Back

MEDIUM

Drupal core - Moderately critical - Gadget chain - SA-CORE-2026-006

Published Jul 10, 2026

Description

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner drupal
Published Jul 10, 2026
Updated Jul 13, 2026
Reserved Jun 17, 2026
CISA Vulnrichment
Updated Jul 13, 2026
NVD
Status Analyzed
Modified Jul 16, 2026
Red Hat
Severity n/a
Public date n/a