Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-12535: Drupal Formatter Field: Malicious Data Injection Risk

DRUPAL-CONTRIB-2026-048 CVE-2026-12535 CVE-2026-12535
Summary

An attacker with permission to edit certain content in Drupal can inject malicious data into the Formatter Field. This can happen when the core JSON:API module is misconfigured. To stay safe, ensure only authorized users have edit access to content with the Formatter Field, and review JSON:API settings to prevent unauthorized field edits.

What to do
  • Update drupal drupal/formatter_field to version 2.0.0.
Affected software
Ecosystem VendorProductAffected versions
Packagist:https://packages.drupal.org/8 drupal drupal/formatter_field < 2.0.0
Fix: upgrade to 2.0.0
– drupal formatter field < 2.0.0
Original title
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter Field allows Object Injection. This issue affects Formatter Field versions: from 0.0...
Original description
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter Field allows Object Injection. This issue affects Formatter Field versions: from 0.0.0 to 2.0.0.
Vulnerability type
CWE-915
Published: 10 Jul 2026 · Updated: 20 Jul 2026 · First seen: 17 Jun 2026