CVE-2026-12535
drupal/formatter_field: Improperly Controlled Modification of Dynamically-Determined Object Attributes (CVE-2026-12535)
criticalEPSS 0.6%
Description
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter Field allows Object Injection. This issue affects Formatter Field versions: from 0.0.0 to 2.0.0.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
packagist:https://packages.drupal.org/8drupal/formatter_field
Metrics
Show all metrics
Severity
critical
87.19
no public PoC known
9.8
Published
2026-07-10 21:43 UTC
CWE-915
Weakness classes (CWE)
CWE-915Base
Improperly Controlled Modification of Dynamically-Determined Object Attributes
The product receives input from an upstream component that specifies multiple attributes, properties, or fields that are to be initialized or updated in an object, but it does not properly control which attributes can be modified.
cwe.mitre.org →