Vulnerability Intelligence Report
Drupal core - Critical - PHP object injection - SA-CORE-2026-005
CVE-2026-55803
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.
No Active Exploit Signals
CVSS Base Score
5.9
MEDIUM
Exploitability:0.8
Impact Score:5.2
EPSS Probability:0.16%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-915 ↗CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Drupal | Drupal core | 0.0.0 < 10.5.12 (affected), 10.6.0 < 10.6.11 (affected), 11.2.0 < 11.2.14 (affected), 11.3.0 < 11.3.12 (affected), 0.0.0 < 11.0.* (affected), 0.0.0 < 11.1.* (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.161%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Drupal.org · Vendor · USA |
| Reserved | 2026-06-17T14:59:52 |
| Published | 2026-07-10T21:46:38 |
| Patch Date | 2026-06-17 |
| Last Updated | 2026-07-13T18:24:17 |
Community Chatter & Buzz