Motiya Co., Ltd. has issued an urgent advisory for organizations using Drupal following the release of the official Drupal Core security advisory SA-CORE-2026-004 by Drupal.org. The company specifically calls for immediate impact assessment and update verification for sites running on PostgreSQL databases.
The vulnerability, identified as CVE-2026-9082, is an SQL injection flaw with a 'Highly critical' risk assessment of 20/25. According to Drupal.org, crafted requests can trigger arbitrary SQL injection on PostgreSQL-based sites, potentially leading to information disclosure, privilege escalation, remote code execution (RCE), and other severe attacks. Notably, this vulnerability is exploitable by anonymous users.
While this SQL injection specifically affects PostgreSQL environments, Drupal.org recommends that all site administrators—regardless of their database type—review the latest release and update policies as part of standard security maintenance.
Leading up to the official announcement, Motiya published detailed articles explaining the preliminary warning, the significance of the risk assessment, and historical case studies of major vulnerabilities. Following the formal release, Motiya is reinforcing its call for immediate action by Drupal users.
### Overview of the Security Advisory - **Advisory:** SA-CORE-2026-004 - **Official Title:** Drupal core - Highly critical - SQL injection - SA-CORE-2026-004 - **Release Date:** May 20, 2026 UTC (Early hours of May 21, Japan Time) - **CVE:** CVE-2026-9082 - **Risk Assessment:** Highly critical 20/25 - **Primary Target:** Drupal sites using PostgreSQL databases - **Exploitation Condition:** Exploitable by anonymous users - **Potential Impact:** Information disclosure, privilege escalation, remote code execution, etc.
This case has drawn significant attention as the first 'Highly critical' advisory for Drupal Core since SA-CORE-2019-003 in 2019. Motiya highlights the exceptional nature of this event and the necessity of immediate response post-disclosure. Organizations that have not received notifications from their administrators or are unsure whether they use PostgreSQL should verify their system configuration urgently.
FACT BOX
- Source: PR TIMES
- Category: News
- Organizations: Drupal.org
- Products / services: Drupal Core / PostgreSQL