CVE-2026-55804
published 2026-07-10CVE-2026-55804: Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects…
PriorityP337medium5.9CVSS 3.1
AVNACHPRHUINSUCHIHAN
EPSS
0.35%
28.3th percentile
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| drupal | drupal | < 10.5.12 | 10.5.12 |
| drupal | drupal | >= 10.6.0 < 10.6.11 | 10.6.11 |
| drupal | drupal | >= 11.0.0 < 11.2.14 | 11.2.14 |
| drupal | drupal | >= 11.3.0 < 11.3.12 | 11.3.12 |
| drupal | drupal_core | — | — |
| drupal | drupal_core | >= 0.0.0 < 10.5.12 | 10.5.12 |
| drupal | drupal_core | >= 0.0.0 < 11.0.* | 11.0.* |
| drupal | drupal_core | >= 0.0.0 < 11.1.* | 11.1.* |
| drupal | drupal_core | >= 10.6.0 < 10.6.11 | 10.6.11 |
| drupal | drupal_core | >= 11.2.0 < 11.2.14 | 11.2.14 |
| drupal | drupal_core | >= 11.3.0 < 11.3.12 | 11.3.12 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.
ghsa_unreviewed·2026-07-11
CVE-2026-55804 CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.
VulDB
Drupal up to 11.3.11 injection
vuldb·2026-07-11
CVE-2026-55804 [CRITICAL] Drupal up to 11.3.11 injection
A vulnerability marked as critical has been reported in Drupal up to 11.3.11. The impacted element is an unknown function. Performing a manipulation results in injection.
This vulnerability was named CVE-2026-55804. The attack may be initiated remotely. There is no available exploit.
Drupal
Drupal core - Moderately critical - Gadget chain - SA-CORE-2026-006
vendor_drupal·2026-06-17
CVE-2026-55804 [MEDIUM] Drupal core - Moderately critical - Gadget chain - SA-CORE-2026-006
Title: Drupal core - Moderately critical - Gadget chain - SA-CORE-2026-006
Vulnerability Type: Gadget chain
Description: Drupal core contains a chain of methods that could be exploitable when an insecure deserialization vulnerability exists on the site. This so-called "gadget chain" presents no direct threat, but is a vector that can be used to achieve remote code execution or SQL injection if the application deserializes untrusted data due to another vulnerability. This issue is not directly exploitable. This issue is mitigated by the fact that in order for it to be exploitable, a separate vulnerability must be present to allow an attacker to pass unsafe input to unserialize() .
Solution: Install the latest version: Drupal 11 If you use Drupal 11.3.x, update to Drupal 11.3.12 . If you
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-10
Published