PT-2026-50607 · Packagist · Drupal Core

Published

2026-06-17

·

Updated

2026-06-17

·

CVE-2026-55804

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Drupal core contains a chain of methods that could be exploitable when an insecure deserialization vulnerability exists on the site. This so-called "gadget chain" presents no direct threat, but is a vector that can be used to achieve remote code execution or SQL injection if the application deserializes untrusted data due to another vulnerability.
This issue is not directly exploitable.
This issue is mitigated by the fact that in order for it to be exploitable, a separate vulnerability must be present to allow an attacker to pass unsafe input to unserialize().
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-55804
DRUPAL-CORE-2026-006

Affected Products

Drupal Core