CVE-2026-12535
Critical · CVSS 9.8drupal/formatter_field — Improperly Controlled Modification of Dynamically-Determined Object Attributes (Object Injection)
- CVSS
- 9.8
- nvd
- EPSS
- 0.39%
- 31th pct
- KEV
- No
- Class
- oss containerizable
- CWE-915
Description
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter Field allows Object Injection. This issue affects Formatter Field versions: from 0.0.0 to 2.0.0.
Search profile — drives PoC discovery
Symbols formatter_fieldsa-contrib-2026-048CWE-915Object Injectionpackages.drupal.org/8drupal/formatter_field
Keywords CVE-2026-12535drupal formatter_fieldobject injectionCWE-915Drupal sa-contrib-2026-048formatter_field exploitDrupal mass assignmentdynamically determined object attributesPackagist drupal formatter_field PoC
Versions: 0.0.0 to 2.0.0
Affected packages
| Packagist:https://packages.drupal.org/8 | drupal/formatter_field | 0 → 2.0.0 |
References
Status: enriched · ingested 2026-07-13T18:00:21.000Z · profiled 2026-07-13T18:30:21.000Z