Answer in brief
CVE-2026-6366 records a Medium severity security vulnerability in Drupal core allows Object Injection. The source record does not mark it as known exploited. 4 affected packages are mapped in the feed.
Answer in brief
CVE-2026-6366 records a Medium severity security vulnerability in Drupal core allows Object Injection. The source record does not mark it as known exploited. 4 affected packages are mapped in the feed.
Update drupal/core to 10.5.9; drupal/core to 10.6.7; drupal/core to 11.2.11; drupal/core to 11.3.7 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanVulnerability describes the vulnerability class recorded for this advisory. The current record does not mark CVE-2026-6366 as known exploited; continue to monitor the source for status changes. The feed includes package mappings that can be checked against lockfiles and deployed manifests.
| Package | Affected range | Fixed version |
|---|---|---|
| drupal/corecomposer | >=8.0.0,<10.5.9 | 10.5.9 |
| drupal/corecomposer | >=10.6.0,<10.6.7 | 10.6.7 |
| drupal/corecomposer | >=11.0.0,<11.2.11 | 11.2.11 |
| drupal/corecomposer | >=11.3.0,<11.3.7 | 11.3.7 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core: from 8.0.0 before 10.5.9, from 10.6.0 before 10.6.7, from 11.0.0 before 11.2.11, from 11.3.0 before 11.3.7.
Reported by GitHub Security Advisories (ghsa).
CVE-2026-6366 records a Medium severity security vulnerability in Drupal core allows Object Injection. The source record does not mark it as known exploited. 4 affected packages are mapped in the feed.
The source record does not mark it as known exploited.
Check lockfiles and deployed manifests for drupal/core, drupal/core, drupal/core.
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL GuardUpdate drupal/core to 10.5.9; drupal/core to 10.6.7; drupal/core to 11.2.11; drupal/core to 11.3.7 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanVulnerability describes the vulnerability class recorded for this advisory. The current record does not mark CVE-2026-6366 as known exploited; continue to monitor the source for status changes. The feed includes package mappings that can be checked against lockfiles and deployed manifests.
| Package | Affected range | Fixed version |
|---|---|---|
| drupal/corecomposer | >=8.0.0,<10.5.9 | 10.5.9 |
| drupal/corecomposer | >=10.6.0,<10.6.7 | 10.6.7 |
| drupal/corecomposer | >=11.0.0,<11.2.11 | 11.2.11 |
| drupal/corecomposer | >=11.3.0,<11.3.7 | 11.3.7 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core: from 8.0.0 before 10.5.9, from 10.6.0 before 10.6.7, from 11.0.0 before 11.2.11, from 11.3.0 before 11.3.7.
Reported by GitHub Security Advisories (ghsa).
CVE-2026-6366 records a Medium severity security vulnerability in Drupal core allows Object Injection. The source record does not mark it as known exploited. 4 affected packages are mapped in the feed.
The source record does not mark it as known exploited.
Check lockfiles and deployed manifests for drupal/core, drupal/core, drupal/core.
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard