Object Injection Vulnerability in Drupal Flag Attendance Field
CVE-2026-55809
8.1HIGH
What is CVE-2026-55809?
The vulnerability in the Drupal Flag attendance field is a result of improperly controlled modifications of object attributes, which can lead to object injection. This security flaw could potentially allow an attacker to manipulate the functionality of the application, leading to unforeseen consequences. Web developers and administrators using affected versions must implement the recommended patches to ensure the integrity of their applications.
Affected Version(s)
Flag attendance field 0.0.0 < 1.2
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Drew Webber (mcdruid)
Anas Mawlawi (anas_maw)
Benji Fisher (benjifisher)
Drew Webber (mcdruid)
Benji Fisher (benjifisher)
Drew Webber (mcdruid)
Jess (xjm)
