Drupal core – Critical – PHP object injection – SA-CORE-2026-005

SecurityVulns

Project: Drupal coreDate: 2026-June-17Security risk: Critical 18 ∕ 25 AC:None/A:User/CI:All/II:All/E:Theoretical/TD:UncommonVulnerability: PHP object injectionAffected versions: <10.5.12 || >=10.6.0 <10.6.11 || >=11.2.0 <11.2.14 || >=11.3.0 <11.3.12 || 11.0.* || 11.1.*CVE IDs: CVE-2026-55803Description: SA-CORE-2019-003 added protection for fields that store serialized data to disallow direct writes via web services.
The above fix did not cover all potential attack vectors for JSON:API. An attacker with appropriate JSON:API write permission could potentially inject a malicious payload in certain rare circumstances, potentially resulting in PHP Object Injection.
This vulnerability is mitigated by the fact that in order to be exploitable:

A site must use an entity reference field type that stores a serialized property.
An attacker must have permission to write to the entity via JSON:API.

No field type shipped with Drupal core meets these criteria, and contributed or user-created field types that do appear to be extremely unusual. This update protects all such fields; no changes are required in contributed modules.
JSON:API is read-only by default, so sites are only affected if they have enabled write access (either through administrator configuration or the installation of a contributed or custom module that enables write access).
Drupal Steward protection:
This issue is being protected by Drupal Steward. In this instance, we believe that the WAF rule will provide mitigation for the common/obvious vulnerability paths, but may not be able to cover all cases or work for all hosting providers. Additionally, several other core security advisories released today are not mitigated by Drupal Steward. Therefore, our recommended action is still to plan an actual Drupal update within 24 hours of this release.Solution: Install the latest version:
Drupal 11

If you use Drupal 11.3.x, update to Drupal 11.3.12.
If you use Drupal 11.2.x, update to Drupal 11.2.14.

Drupal 10

If you use Drupal 10.6.x, update to Drupal 10.6.11.
If you use Drupal 10.5.x, update to Drupal 10.5.12.

Drupal 11.1.x, Drupal 11.0.x, Drupal 10.4.x, and below are end-of-life and do not receive security coverage. (Drupal 8 and Drupal 9 have both reached end-of-life.)Reported By: 
Michael Maturi (michaelmaturi)
Fixed By: 
Björn Brala (bbrala)
Sascha Grossenbacher (berdir)
Lee Rowlands (larowlan) of the Drupal Security Team
Dave Long (longwave) of the Drupal Security Team
Drew Webber (mcdruid) of the Drupal Security Team
Coordinated By: 
Anna Kalata (akalata) of the Drupal Security Team
Benji Fisher (benjifisher) of the Drupal Security Team
Damien McKenna (damienmckenna) of the Drupal Security Team
David Strauss (david strauss) of the Drupal Security Team
Neil Drumm (drumm) of the Drupal Security Team
Greg Knaddison (greggles) of the Drupal Security Team
Tim Hestenes Lehnen (hestenet)
Lee Rowlands (larowlan) of the Drupal Security Team
Dave Long (longwave) of the Drupal Security Team
Drew Webber (mcdruid) of the Drupal Security Team
Juraj Nemec (poker10) of the Drupal Security Team
Ra Mänd (ram4nd) provisional member of the Drupal Security Team
Jess (xjm) of the Drupal Security TeamSecurity advisoriesRead More