← Back to CVE List
Vulnerability Intelligence Report
Drupal core - Critical - PHP object injection - SA-CORE-2026-005

CVE-2026-55803

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.

No Active Exploit Signals
CVSS Base Score
5.9
MEDIUM
Exploitability:0.8
Impact Score:5.2
EPSS Probability:0.16%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-915 ↗CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes

Affected Products & Versions

Vendor Product Affected Versions
Drupal Drupal core 0.0.0 < 10.5.12 (affected), 10.6.0 < 10.6.11 (affected), 11.2.0 < 11.2.14 (affected), 11.3.0 < 11.3.12 (affected), 0.0.0 < 11.0.* (affected), 0.0.0 < 11.1.* (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.161%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityDrupal.org · Vendor · USA
Reserved2026-06-17T14:59:52
Published2026-07-10T21:46:38
Patch Date2026-06-17
Last Updated2026-07-13T18:24:17

LINK COPIED TO CLIPBOARD