CVE-2026-9726
drupal/basket: Improperly Controlled Modification of Dynamically-Determined Object Attributes (CVE-2026-9726)
Description
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal AlternativeCommerce (Basket) allows Object Injection. This issue affects Drupal AlternativeCommerce (Basket) versions: from 0.0.0 to 2.1.17.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
Metrics
Show all metrics
Weakness classes (CWE)
CWE-915Base
Improperly Controlled Modification of Dynamically-Determined Object Attributes
The product receives input from an upstream component that specifies multiple attributes, properties, or fields that are to be initialized or updated in an object, but it does not properly control which attributes can be modified.
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- Initial Analysis2026-08-06 18:28 UTC· nvd@nist.gov
- CPE Configuration: OR *cpe:2.3:a:alternativecommerce:alternativecommerce:*:*:*:*:*:drupal:*:* versions up to (excluding) 2.1.17
- Reference Type: Drupal.org: https://www.drupal.org/sa-contrib-2026-038 Types: Vendor Advisory