CVE-2026-55806Patch(drupal / drupal)

LOWCVSS 5.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch drupal drupal systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-601

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • drupal

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
drupal

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-18: 1Patch / Workaround · 2026-06-18: 1Technical Details · 2026-06-18: 106-18
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Autumn Good@autumn_good_35
    Patch

    『This could result in cache poisoning or a redirect to an attacker-controlled domain.』 CVE-2026-55806 Drupal core - Less critical - Cache poisoning and open redirect - SA-CORE-2026-007 https://www.drupal.org/sa-core-2026-007

    Post summary

    The advisory discloses a cache poisoning and open redirect vulnerability in Drupal core (CVE-2026-55806) and indicates a fix is available via the linked Drupal Security Advisory.

    00000295
    6.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdrupaldrupal---

Explore more