Boletines de Vulnerabilidades

CVE-2026-6366

   
Software afectado DRUPAL
 
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.

This issue affects Drupal core: from 8.0.0 before 10.5.9, from 10.6.0 before 10.6.7, from 11.0.0 before 11.2.11, from 11.3.0 before 11.3.7.

Link:

https://nvd.nist.gov/vuln/detail/CVE-2026-6366