CVE-2026-9726
Critical · CVSS 9.8Drupal AlternativeCommerce (Basket) — Improperly Controlled Modification of Dynamically-Determined Object Attributes (Object Injection / Mass Assignment)
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-915
Description
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal AlternativeCommerce (Basket) allows Object Injection. This issue affects Drupal AlternativeCommerce (Basket) versions: from 0.0.0 to 2.1.17.
Search profile — drives PoC discovery
Symbols drupal/basketBasketAlternativeCommerceObject InjectionCWE-915sa-contrib-2026-038packages.drupal.org/8
Keywords CVE-2026-9726Drupal Basket exploitDrupal AlternativeCommerce PoCdrupal/basket object injectionCWE-915 Drupalsa-contrib-2026-038 PoCDrupal Basket mass assignmentDrupal Basket 2.1.17 vulnerability
Versions: 0.0.0 to 2.1.17
Affected packages
| Packagist:https://packages.drupal.org/8 | drupal/basket | 0 → 2.1.17 |
References
Status: enriched · ingested 2026-07-14T18:00:20.000Z · profiled 2026-07-15T06:30:20.000Z