CVE-2026-12535

drupal/formatter_field: Improperly Controlled Modification of Dynamically-Determined Object Attributes (CVE-2026-12535)

criticalEPSS 0.6%

Description

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter Field allows Object Injection. This issue affects Formatter Field versions: from 0.0.0 to 2.0.0.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

packagist:https://packages.drupal.org/8drupal/formatter_field

Metrics

9.8
Source: nvd-v3
45.2 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
critical
no public PoC known
0.6 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-07-10 21:43 UTC
CWE-915

Weakness classes (CWE)

  • CWE-915Base

    Improperly Controlled Modification of Dynamically-Determined Object Attributes

    The product receives input from an upstream component that specifies multiple attributes, properties, or fields that are to be initialized or updated in an object, but it does not properly control which attributes can be modified.

    cwe.mitre.org →

References & sources

Linked advisories