Back

MEDIUM

Drupal core - Moderately critical - Gadget Chain - SA-CORE-2026-002

Published May 19, 2026

Description

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.

This issue affects Drupal core: from 8.0.0 before 10.5.9, from 10.6.0 before 10.6.7, from 11.0.0 before 11.2.11, from 11.3.0 before 11.3.7.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner drupal
Published May 19, 2026
Updated May 21, 2026
Reserved Apr 15, 2026
CISA Vulnrichment
Updated May 20, 2026
NVD
Status Analyzed
Modified Jul 24, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-XMJC-63PR-2MPG