Junglewise Threat Intelligence

CVE-2026-55803: Drupal core PHP object injection in JSON:API

CVE-2026-55803 · Severity: info · CVSS 8.8 · Published 2026-07-10

Technologies: Drupal, Drupal Core, drupal/core (Packagist). Vendors: Drupal, Packagist.

Executive brief

Drupal is a popular open-source content management system used to build and manage websites. A critical security flaw has been identified where an attacker with permission to modify content via the JSON:API could inject malicious code into the system. If exploited, this could allow an attacker to take full control of the website, potentially leading to data theft or service disruption. This vulnerability is mitigated by the fact that it requires specific, non-standard configurations to be exploitable.

Technical details

A PHP Object Injection vulnerability exists in Drupal core's JSON:API implementation due to improper validation of dynamically-determined object attributes (CWE-915). While a previous fix (SA-CORE-2019-003) protected fields storing serialized data from direct writes, it did not cover all attack vectors within JSON:API. An attacker with JSON:API write permissions can exploit this if the site uses an entity reference field type that stores a serialized property. Successful exploitation allows the injection of a malicious payload, potentially leading to remote code execution. The vulnerability is mitigated because JSON:API is read-only by default and no standard Drupal core field types meet the specific criteria for exploitation. Patches are available in versions 10.5.12, 10.6.11, 11.2.14, and 11.3.12.

Affected products

  • Drupal Drupal core < 10.5.12, 10.6.x < 10.6.11, 11.2.x < 11.2.14, 11.3.x < 11.3.12, 11.0.x, 11.1.x

Timeline

  • 2026-06-17: advisory: Drupal security advisory SA-CORE-2026-005 released
  • 2026-07-10: disclosed: CVE-2026-55803 published to NVD

References

Related threats