Junglewise Threat Intelligence

CVE-2026-6366: Drupal Drupal core Object Injection gadget chain

CVE-2026-6366 · Severity: medium · CVSS 6.6 · Published 2026-05-19

Technologies: Drupal Core, Drupal, drupal/core (Packagist). Vendors: Drupal, Packagist.

Executive brief

Drupal core contains a 'gadget chain' that could allow an attacker to take full control of a website. This vulnerability is not directly exploitable on its own; it requires the presence of a second, separate flaw that allows the site to process untrusted data. If both conditions are met, an attacker could potentially execute malicious code or access sensitive database information.

Technical details

Drupal core is vulnerable to PHP Object Injection via a 'gadget chain' (CWE-915). The vulnerability exists in a chain of methods that can be triggered if the application deserializes untrusted data. While not directly exploitable on its own, it serves as a secondary vector that enables Remote Code Execution (RCE) or SQL injection when combined with a primary insecure deserialization flaw. Exploitation requires a high-privileged network attacker and high attack complexity due to the prerequisite of a separate vulnerability. Patches are available in Drupal versions 10.5.9, 10.6.7, 11.2.11, and 11.3.7.

Affected products

  • Drupal Drupal core 8.0.0 to 10.5.8, 10.6.0 to 10.6.6, 11.0.0 to 11.2.10, 11.3.0 to 11.3.6

Timeline

  • 2026-04-15: advisory: Original Drupal security advisory date
  • 2026-05-19: disclosed: NVD publication date
  • 2026-05-20: advisory: GitHub Advisory Database publication date

References

Related threats