CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-12535

Critical · CVSS 9.8

drupal/formatter_field — Improperly Controlled Modification of Dynamically-Determined Object Attributes (Object Injection)

CVSS
9.8
nvd
EPSS
0.39%
31th pct
KEV
No
Class
oss containerizable
CWE-915

Description

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter Field allows Object Injection. This issue affects Formatter Field versions: from 0.0.0 to 2.0.0.

Search profile — drives PoC discovery

Symbols formatter_fieldsa-contrib-2026-048CWE-915Object Injectionpackages.drupal.org/8drupal/formatter_field
Keywords CVE-2026-12535drupal formatter_fieldobject injectionCWE-915Drupal sa-contrib-2026-048formatter_field exploitDrupal mass assignmentdynamically determined object attributesPackagist drupal formatter_field PoC
Versions: 0.0.0 to 2.0.0

Affected packages

Packagist:https://packages.drupal.org/8 drupal/formatter_field 0 → 2.0.0

References

Status: enriched · ingested 2026-07-13T18:00:21.000Z · profiled 2026-07-13T18:30:21.000Z