Description
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.
Published: 2026-07-10
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Drupal core contains an Improperly Controlled Modification of Dynamically-Determined Object Attributes flaw (CWE‑915). When an attacker can influence data sent to Drupal, the system may create or modify object properties in unintended ways, allowing an attacker to inject arbitrary object attributes. The result can be unauthorized changes to application data or configuration, but the CVE description does not state or imply execution of arbitrary code.

Affected Systems

The flaw applies to every Drupal core installation whose version falls within the following ranges: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, and to every release in the 11.0.* and 11.1.* branches.

Risk and Exploitability

The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low likelihood of current exploitation. The CVSS score of 5.9 reflects moderate severity, driven by the potential for data tampering. The attack vector is inferred to be a remote web request that supplies crafted data to the application; the presence of instructed object injection makes an attacker able to alter key application state if the vector is successfully exercised.

Generated by OpenCVE AI on July 29, 2026 at 09:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Drupal core to the earliest patched release in the affected series (10.5.13, 10.6.12, 11.2.15, 11.3.13, or any newer 11.0 or 11.1 release).
  • Update all contributed modules and themes to versions that are compatible with the patched core to eliminate third‑party entry points that could manipulate object attributes.
  • Audit custom code that interacts with object properties for unintended instantiations or dynamic assignments, and review logs for signs of suspicious activity following the upgrade.

Generated by OpenCVE AI on July 29, 2026 at 09:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 13 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 11 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Drupal
Drupal drupal Core
Vendors & Products Drupal
Drupal drupal Core

Fri, 10 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.
Title Drupal core - Moderately critical - Gadget chain - SA-CORE-2026-006
Weaknesses CWE-915
References

Subscriptions

Drupal Drupal Core
cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-07-13T18:23:35.057Z

Reserved: 2026-06-17T14:59:52.673Z

Link: CVE-2026-55804

cve-icon Vulnrichment

Updated: 2026-07-13T18:23:31.240Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T09:45:04Z

Weaknesses
  • CWE-915

    Improperly Controlled Modification of Dynamically-Determined Object Attributes