SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-12535

CRITICAL · CVSS 9.8 EPSS 0.39%

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

The vulnerability in Drupal's Formatter Field allows for improper control over dynamically-determined object attributes, leading to potential object injection attacks. This critical flaw, affecting versions 0.0.0 to 2.0.0, could enable an attacker to manipulate object attributes, compromising the integrity and security of the application. Organizations using affected versions should prioritize immediate remediation to mitigate the risk of exploitation.

CVE
CVE-2026-12535
Severity
CRITICAL
CVSS
9.8
EPSS
0.39%

Original NVD Description

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter Field allows Object Injection. This issue affects Formatter Field versions: from 0.0.0 to 2.0.0.