cbcvebase.
CVE-2026-55804
published 2026-07-10

CVE-2026-55804: Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects…

PriorityP337medium5.9CVSS 3.1
AVNACHPRHUINSUCHIHAN
EPSS
0.35%
28.3th percentile
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.

Affected

11 ranges
VendorProductVersion rangeFixed in
drupaldrupal< 10.5.1210.5.12
drupaldrupal>= 10.6.0 < 10.6.1110.6.11
drupaldrupal>= 11.0.0 < 11.2.1411.2.14
drupaldrupal>= 11.3.0 < 11.3.1211.3.12
drupaldrupal_core
drupaldrupal_core>= 0.0.0 < 10.5.1210.5.12
drupaldrupal_core>= 0.0.0 < 11.0.*11.0.*
drupaldrupal_core>= 0.0.0 < 11.1.*11.1.*
drupaldrupal_core>= 10.6.0 < 10.6.1110.6.11
drupaldrupal_core>= 11.2.0 < 11.2.1411.2.14
drupaldrupal_core>= 11.3.0 < 11.3.1211.3.12
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.