Junglewise Threat Intelligence

CVE-2026-15086: Drupal Raw Formatter unpatched critical vulnerability

CVE-2026-15086 · Severity: info · CVSS 7.2 · Published 2026-07-10

Vendors: Packagist:Https://Packages.Drupal.Org/8, Drupal.

Executive brief

The Drupal Raw Formatter (Meta Tag Formatter) module has been marked as unsupported due to an unpatched critical security vulnerability. This module is used to provide raw field formatting for meta tags in Drupal REST export views. Because the maintainer has not addressed the security flaw, the Drupal Security Team recommends uninstalling the module immediately to prevent potential site compromise or data loss.

Technical details

The Drupal Raw Formatter [Meta Tag Formatter] module is subject to a critical security vulnerability that remains unpatched. While the specific vulnerability class (e.g., XSS, SQLi) is not explicitly detailed in the advisory, the Drupal Security Team has assigned it a 'Critical' risk rating (16/25) and issued an 'Unsupported' advisory (SA-CONTRIB-2026-077). The vulnerability affects all versions of the module. Due to the lack of a fix from the maintainer, the project has been marked as unsupported, and users are advised to uninstall the module or migrate to an alternative solution.

Affected products

  • Drupal Raw Formatter [Meta Tag Formatter] All versions

Timeline

  • 2026-07-08: advisory: Drupal Security Team issues SA-CONTRIB-2026-077 marking the project unsupported due to security issues.
  • 2026-07-10: disclosed: CVE-2026-15086 is published.

References