Drupal core - Moderately critical - Improper validation - SA-CORE-2026-009
Project: Drupal core Date: 2026-June-17 Security risk: Moderately critical 11 ∕ 25 AC:Complex/A:User/CI:Some/II:Some/E:Theoretical/TD:Uncommon Vulnerability: Improper validation Affected versions: <10.5.12 || >=10.6.0 <10.6.11 || >=11.2.0 <11.2.14 || >=11.3.0 <11.3.12 || 11.0.* || 11.1.* CVE IDs: CVE-2026-55808 Description: The JSON:API and REST modules allow you to upload image files to image fields. The validation rules check the file extension of the uploaded file but not the file MIME type. This may allow a malicious user to upload a file that is not an image. Certain web-server configurations may serve the uploaded file with its actual MIME type rather than an image type. This may lead to cross-site scripting (XSS) or other unexpected behavior. Solution: Install the latest version: Drupal 11 If you use Drupal 11.3.x, update to Drupal 11.3.12 . If you use Drupal 11.2.x, update to Drupal 11.2.14 . Drupal 10 If you use Drupal 10.6.x, update to Drupal 10.6.11 . If you use Drupal 10.5.x, update to Drupal 10.5.12 . Drupal 11.1.x, Drupal 11.0.x, Drupal 10.4.x, and below are end-of-life and do not receive security coverage. ( Drupal 8 and Drupal 9 have both reached end-of-life.) Reported By: cantina_security Fixed By: Björn Brala (bbrala) Kim Pepper (kim.pepper) Lee Rowlands (larowlan) of the Drupal Security Team Coordinated By: Damien McKenna (damienmckenna) of the Drupal Security Team Greg Knaddison (greggles) of the Drupal Security Team Lee Rowlands (larowlan) of the Drupal Security Team Dave Long (longwave) of the Drupal Security Team Juraj Nemec (poker10) of the Drupal Security Team Jess (xjm) of the Drupal Security Team
CSIRTS triage
- What
- Improper validation allows for potential cross-site scripting (XSS) or other unexpected behavior.
- Who is affected
- Users of affected Drupal core versions.
- Urgency
- Critical remediation is needed due to the severity of the vulnerability.
- Action
- Update to the latest version of Drupal or the specified versions.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Drupal core
Get an email when a new Drupal core advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.drupal.org/sa-core-2026-009
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-558080.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-55808 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for Drupal core -
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownCVE-2026-55805: Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerabi…nvd · 2026-08-25
- unknownCVE-2026-15917: Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerabi…nvd · 2026-08-25
- unknownCVE-2026-15916: Missing Authorization vulnerability in Drupal Drupal core allows Forceful Browsing. This issue…nvd · 2026-08-25
- medium[NEW] [medium] Drupal Core: Multiple vulnerabilitiescert-bund · 2026-07-16
- criticalDrupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-012drupal · 2026-07-15
- criticalDrupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-011drupal · 2026-07-15
More from Drupal Security Advisories
- criticalDrupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-0122026-07-15
- criticalDrupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-0112026-07-15
- criticalDrupal core - Moderately critical - Information disclosure - SA-CORE-2026-0102026-07-15
- criticalDrupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-0082026-06-17
- criticalDrupal core - Less critical - Cache poisoning and open redirect - SA-CORE-2026-0072026-06-17