Web Hack List

Preliminary research

Keys to the Kingdom: Anonymous SQL Injection in Drupal Core (CVE-2026-9082)

AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.

Traces attacker-controlled array keys through Drupal’s PostgreSQL-specific case-insensitive IN translation, where SQL placeholders are rebuilt outside generic normalization. JSON login and JSON:API examples expose anonymous reachability, and a conditional database error supplies an extraction oracle under the relevant endpoint and backend settings.

Record

Researcher
Patrik Grobshäuser, Kevin Gervot and Tomais Williamson
Published by
Searchlight Cyber
Topic
Injection

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Patrik Grobshäuser, Kevin Gervot and Tomais Williamson, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .