CVE-2026-9726

drupal/basket: Improperly Controlled Modification of Dynamically-Determined Object Attributes (CVE-2026-9726)

criticalEPSS 0.6%

Description

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal AlternativeCommerce (Basket) allows Object Injection. This issue affects Drupal AlternativeCommerce (Basket) versions: from 0.0.0 to 2.1.17.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

packagist:https://packages.drupal.org/8drupal/basket

Metrics

9.8
Source: nvd-v3
45.2 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
critical
no public PoC known
0.6 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-07-10 21:17 UTC
CWE-915

Weakness classes (CWE)

  • CWE-915Base

    Improperly Controlled Modification of Dynamically-Determined Object Attributes

    The product receives input from an upstream component that specifies multiple attributes, properties, or fields that are to be initialized or updated in an object, but it does not properly control which attributes can be modified.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. Initial Analysis2026-08-06 18:28 UTC· nvd@nist.gov
    • CPE Configuration: OR *cpe:2.3:a:alternativecommerce:alternativecommerce:*:*:*:*:*:drupal:*:* versions up to (excluding) 2.1.17
    • Reference Type: Drupal.org: https://www.drupal.org/sa-contrib-2026-038 Types: Vendor Advisory

Linked advisories