CVE-2026-55803
published 2026-07-10CVE-2026-55803: Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects…
PriorityP337medium5.9CVSS 3.1
AVNACHPRHUINSUCHIHAN
EPSS
0.35%
28.3th percentile
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| drupal | drupal | < 10.5.12 | 10.5.12 |
| drupal | drupal | >= 10.6.0 < 10.6.11 | 10.6.11 |
| drupal | drupal | >= 11.0.0 < 11.2.14 | 11.2.14 |
| drupal | drupal | >= 11.3.0 < 11.3.12 | 11.3.12 |
| drupal | drupal_core | — | — |
| drupal | drupal_core | >= 0.0.0 < 10.5.12 | 10.5.12 |
| drupal | drupal_core | >= 0.0.0 < 11.0.* | 11.0.* |
| drupal | drupal_core | >= 0.0.0 < 11.1.* | 11.1.* |
| drupal | drupal_core | >= 10.6.0 < 10.6.11 | 10.6.11 |
| drupal | drupal_core | >= 11.2.0 < 11.2.14 | 11.2.14 |
| drupal | drupal_core | >= 11.3.0 < 11.3.12 | 11.3.12 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Drupal
Drupal core - Critical - PHP object injection - SA-CORE-2026-005
vendor_drupal·2026-06-17
CVE-2026-55803 [HIGH] Drupal core - Critical - PHP object injection - SA-CORE-2026-005
Title: Drupal core - Critical - PHP object injection - SA-CORE-2026-005
Vulnerability Type: PHP object injection
Description: SA-CORE-2019-003 added protection for fields that store serialized data to disallow direct writes via web services. The above fix did not cover all potential attack vectors for JSON:API. An attacker with appropriate JSON:API write permission could potentially inject a malicious payload in certain rare circumstances, potentially resulting in PHP Object Injection. This vulnerability is mitigated by the fact that in order to be exploitable: A site must use an entity reference field type that stores a serialized property. An attacker must have permission to write to the entity via JSON:API. No field type shipped with Drupal core meets these criteria, and contributed o
GHSA
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.
ghsa_unreviewed·2026-07-11
CVE-2026-55803 CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.
VulDB
Drupal up to 11.3.11 Core injection
vuldb·2026-07-11
CVE-2026-55803 [CRITICAL] Drupal up to 11.3.11 Core injection
A vulnerability labeled as critical has been found in Drupal up to 11.3.11. The affected element is an unknown function of the component Core. Such manipulation leads to injection.
This vulnerability is uniquely identified as CVE-2026-55803. The attack can be launched remotely. No exploit exists.
No detection rules found.
No public exploits indexed.
2026-07-10
Published