SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-55804

MEDIUM · CVSS 5.9 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

Drupal core is vulnerable to an improperly controlled modification of dynamically-determined object attributes, leading to potential object injection attacks. This flaw affects multiple versions of Drupal core, specifically from 0.0.0 to 10.5.12 and various ranges up to 11.3.12. Organizations using affected versions should prioritize patching to mitigate the risk of unauthorized access and manipulation of object attributes.

CVE
CVE-2026-55804
Severity
MEDIUM
CVSS
5.9
EPSS
0.21%

Original NVD Description

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.

Related CVEs

Other vulnerabilities affecting the same vendor(s)