Drupal core - Less critical - Cache poisoning and open redirect - SA-CORE-2026-007
Project: Drupal core Date: 2026-June-17 Security risk: Less critical 9 ∕ 25 AC:Basic/A:None/CI:None/II:None/E:Theoretical/TD:Default Vulnerability: Cache poisoning and open redirect Affected versions: <10.5.12 || >=10.6.0 <10.6.11 || >=11.2.0 <11.2.14 || >=11.3.0 <11.3.12 || 11.0.* || 11.1.* CVE IDs: CVE-2026-55806 Description: Drupal core ships a rebuild.php front controller that can be used to rebuild Drupal (clearing the caches and rebuilding the container) when the site is in an unexpected condition. This script doesn't correctly check the Host header against the list of trusted host patterns. This could result in cache poisoning or a redirect to an attacker-controlled domain. Solution: Install the latest version: Drupal 11 If you use Drupal 11.3.x, update to Drupal 11.3.12 . If you use Drupal 11.2.x, update to Drupal 11.2.14 . Drupal 10 If you use Drupal 10.6.x, update to Drupal 10.6.11 . If you use Drupal 10.5.x, update to Drupal 10.5.12 . Drupal 11.1.x, Drupal 11.0.x, Drupal 10.4.x, and below are end-of-life and do not receive security coverage. ( Drupal 8 and Drupal 9 have both reached end-of-life.) Reported By: Melih Acikoz Michael Winser (michaelwinser) Willem Drupal enthousiast (willempje2) Fixed By: Lee Rowlands (larowlan) of the Drupal Security Team Coordinated By: catch (catch) of the Drupal Security Team cilefen (cilefen) of the Drupal Security Team Greg Knaddison (greggles) of the Drupal Security Team Lee Rowlands (larowlan) of the Drupal Security Team Dave Long (longwave) of the Drupal Security Team James Gilliland (neclimdul) of the Drupal Security Team Juraj Nemec (poker10) of the Drupal Security Team Jess (xjm) of the Drupal Security Team
CSIRTS triage
- What
- Cache poisoning and open redirect vulnerability in the rebuild.php front controller.
- Who is affected
- Users of affected Drupal core versions.
- Urgency
- Critical remediation is needed due to the severity of the vulnerability.
- Action
- Update to the latest version of Drupal or the specified versions.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Drupal core
Get an email when a new Drupal core advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.drupal.org/sa-core-2026-007
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-558060.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-55806 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
More from Drupal Security Advisories
- criticalDrupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-0122026-07-15
- criticalDrupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-0112026-07-15
- criticalDrupal core - Moderately critical - Information disclosure - SA-CORE-2026-0102026-07-15
- criticalDrupal core - Moderately critical - Improper validation - SA-CORE-2026-0092026-06-17
- criticalDrupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-0082026-06-17