Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-12535: Drupal Formatter Field: Malicious Data Injection Risk
DRUPAL-CONTRIB-2026-048
CVE-2026-12535
CVE-2026-12535
Summary
An attacker with permission to edit certain content in Drupal can inject malicious data into the Formatter Field. This can happen when the core JSON:API module is misconfigured. To stay safe, ensure only authorized users have edit access to content with the Formatter Field, and review JSON:API settings to prevent unauthorized field edits.
What to do
- Update drupal drupal/formatter_field to version 2.0.0.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Packagist:https://packages.drupal.org/8 | drupal | drupal/formatter_field |
< 2.0.0 Fix: upgrade to 2.0.0
|
| – | drupal | formatter field | < 2.0.0 |
Original title
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter Field allows Object Injection. This issue affects Formatter Field versions: from 0.0...
Original description
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter Field allows Object Injection. This issue affects Formatter Field versions: from 0.0.0 to 2.0.0.
Vulnerability type
CWE-915
Published: 10 Jul 2026 · Updated: 20 Jul 2026 · First seen: 17 Jun 2026