Drupal 10.6.x < 10.6.17 / 11.3.x < 11.3.17 / 11.4.x < 11.4.7 Drupal Vulnerability (SA-CORE-2026-013)

high Nessus Plugin ID 346470

Synopsis

A PHP application running on the remote web server is affected by a vulnerability.

Description

According to its self-reported version, the instance of Drupal running on the remote web server is 10.6.x prior to 10.6.17, 11.3.x prior to 11.3.17, or 11.4.x prior to 11.4.7. It is, therefore, affected by a vulnerability.

- The Drupal project uses the CKEditor library for WYSIWYG editing. CKEditor has released a security update that impacts Drupal. Vulnerabilities are possible if Drupal is configured to use CKEditor for WYSIWYG editing. An attacker that can create or edit content (even without access to CKEditor themselves) may be able to exploit this Cross-Site Scripting (XSS) vulnerability to target users with access to the WYSIWYG CKEditor, including site admins with privileged access. For more information, see CKEditor's security advisory: High-severity Cross-site scripting (XSS) in the engine package (SA-CORE-2026-013)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Drupal version 10.6.17 / 11.3.17 / 11.4.7 or later.

See Also

https://github.com/ckeditor/ckeditor5

https://www.drupal.org/project/drupal/releases/10.6.17

https://www.drupal.org/project/drupal/releases/11.3.17

https://www.drupal.org/project/drupal/releases/11.4.7

https://www.drupal.org/psa-2011-002

https://www.drupal.org/psa-2021-06-29

https://www.drupal.org/psa-2023-11-01

https://www.drupal.org/sa-core-2026-013

http://www.nessus.org/u?2cbd9462

http://www.nessus.org/u?d16581be

Plugin Details

Severity: High

ID: 346470

File Name: drupal_11_4_7.nasl

Version: 1.1

Type: Remote

Family: CGI abuses

Published: 9/16/2026

Updated: 9/16/2026

Configuration: Enable paranoid mode, Enable thorough checks (optional)

Supported Sensors: Nessus

Vulnerability Information

CPE: cpe:/a:drupal:drupal

Required KB Items: Settings/ParanoidReport, installed_sw/Drupal

Exploit Ease: No known exploits are available

Patch Publication Date: 9/16/2026

Vulnerability Publication Date: 9/16/2026