Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal AlternativeCommerce (Basket) allows Obje...
Description
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal AlternativeCommerce (Basket) allows Object Injection. This issue affects Drupal AlternativeCommerce (Basket) versions: from 0.0.0 to 2.1.17.
Remediation
Update Drupal Drupal AlternativeCommerce (Basket) to the latest version. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: Drupal
PRODUCT: Core
AFFECTED_VERSIONS: Drupal core: 8.9.0 through 10.4.9, 10.5.0 through 10.5.9, 10.6.0 through 10.6.8, 11.0.0 through 11.1.9, 11.2.0 through 11.2.11, and 11.3.0 through 11.3.9.
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
A critical SQL injection vulnerability exists in Drupal Core for PostgreSQL backends, allowing unauthenticated attackers to execute arbitrary SQL statements.
Executive Summary:
Drupal Core is affected by a critical SQL injection vulnerability that is currently being exploited in the wild, posing an immediate risk of remote code execution.
Vulnerability Details
CVE-ID: CVE-2026-9082
Affected Software: Drupal Core
Affected Versions: Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.1.10, from 11.2.0 before 11.2.12, and from 11.3.0 before 11.3.10.
Vulnerability: This is an unauthenticated SQL injection vulnerability affecting Drupal sites using PostgreSQL. Attackers can inject malicious SQL via network-accessible inputs, potentially leading to data exfiltration, modification, or remote code execution.
Business Impact
With a CVSS score of 9.5, this vulnerability represents a critical risk. Successful exploitation allows an attacker to bypass authentication, potentially gaining full control over the Drupal instance and the underlying database. This could result in complete loss of data confidentiality, integrity, and availability, as well as unauthorized access to integrated enterprise systems.
Remediation Plan
Immediate Action: Update Drupal core to versions 10.4.10, 10.5.10, 10.6.9, 11.1.10, 11.2.12, or 11.3.10 immediately.
Proactive Monitoring: Review database query logs for anomalous or malformed SQL patterns originating from external sources.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules designed to detect and block SQL injection patterns, though this should be treated only as a temporary measure.
Exploitation Status
Public Exploit Available: True
Analyst Notes: As of May 22, 2026, this vulnerability is listed in the CISA KEV catalog. Extensive exploitation attempts have been recorded globally, confirming that this is an active target for threat actors.
Analyst Recommendation
Given the confirmed active exploitation and the critical nature of this SQL injection flaw, organizations must prioritize patching their Drupal environments immediately. Failure to update will leave systems vulnerable to complete compromise by unauthenticated attackers.