CVE-2026-55804
Drupal core - Moderately critical - Gadget chain - SA-CORE-2026-006
5.9
MEDIUM
CVSS 3.1
EPSS 0.21%
描述
Drupal core contains a chain of methods that could be exploitable when an insecure deserialization vulnerability exists on the site. This so-called "gadget chain" presents no direct threat, but is a vector that can be used to achieve remote code execution or SQL injection if the application deserializes untrusted data due to another vulnerability. This issue is not directly exploitable. This issue is mitigated by the fact that in order for it to be exploitable, a separate vulnerability must be present to allow an attacker to pass unsafe input to `unserialize()`.
如何修補 CVE-2026-55804
要修補 CVE-2026-55804,請將受影響套件升級到下列已修補版本。
- —升級至 10.5.12 或更新版本
- —升級至 10.5.12 或更新版本
CVE-2026-55804 正在被利用嗎?
低 — EPSS 為 0.2%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 10.5.12, >= 10.6.0, < 10.6.11, >= 11.0.0, < 11.2.14, >= 11.3.0, < 11.3.12
- from 0, < 10.5.12 | >= 10.6.0, < 10.6.11 | >= 11.2.0, < 11.2.14 | >= 11.3.0, < 11.3.12 | >= 11.0.0, < 11.1.0 | >= 11.1.0, < 11.2.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.9 | CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N |