Intel

AIKIDO-2026-10568

drupal/core is vulnerable to Deserialization of Untrusted Data

Deserialization of Untrusted DataCVE-2026-6366 Published Apr 27, 2026

60

Medium Risk

This Affects:

PHPdrupal/core
8.0.0 - 10.5.8
Fixed in 10.5.9
10.6.0 - 10.6.6
Fixed in 10.6.7
11.0.0 - 11.2.10
Fixed in 11.2.11
11.3.0 - 11.3.6
Fixed in 11.3.7
Are you affected? Scan for Free

TL;DR

Affected versions of this package contain a deserialization gadget chain that could be leveraged if a separate insecure deserialization vulnerability allows untrusted data to reach unserialize(). While not directly exploitable on its own, the gadget chain may enable remote code execution or SQL injection when combined with another flaw that permits unsafe object deserialization.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

drupal/core is vulnerable to Deserialization of Untrusted Data in versions 8.0.0 - 10.5.8, 10.6.0 - 10.6.6, 11.0.0 - 11.2.10 and 11.3.0 - 11.3.6.

How to fix this

Upgrade the drupal/core library to the patch version.