Report: CVE-2026-6366 - Drupal core - Moderately critical - Gadget Chain - SA-CORE-2026-002 - 2025 Update

Report: CVE-2026-6366 - Drupal core - Moderately critical - Gadget Chain - SA-CORE-2026-002 - 2025 Update

CVE ID :CVE-2026-6366 Published : May 19, 2026, 11:16 p.m. | 51 minutes ago Description :Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core: from 8.0.0 before 10.5.9, from 10.6.0 before 10.6.7, from 11.0.0 before 11.2.11, from 11.3.0 before 11.3.7. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Published
May 19, 2026
Affected Product: Drupal