Junglewise Threat Intelligence

CVE-2026-96376: Drupal Cloud module command injection in Kubernetes integration

CVE-2026-96376 · Severity: info · Published 2026-09-23

Vendors: Packagist:Https://Packages.Drupal.Org/8, Drupal.

Executive brief

The Cloud module for Drupal, which allows administrators to manage cloud resources, fails to properly sanitize Git repository URLs and branch names before passing them to system commands. This enables an authenticated attacker with permissions to edit cloud server templates to execute arbitrary operating system commands with the privileges of the web server user, potentially leading to full system compromise.

Technical details

The vulnerability is a command injection flaw in the Kubernetes submodule where unsanitized user input from Git branch and repository URL fields is directly passed to shell commands. An attacker with "add or edit cloud server templates" permission (and optionally "launch cloud server template" permission depending on the exploitation path) can inject shell metacharacters to execute arbitrary commands as the web server user. The vulnerability affects all versions before 7.0.1.

Affected products

  • Drupal Cloud <7.0.1

Timeline

  • 2026-09-23: disclosed: Security advisory SA-CONTRIB-2026-177 published

References

Related threats