CVE-2026-9726
9.8Drupal · AlternativeCommerce (Basket)
A critical object injection vulnerability exists in the Drupal AlternativeCommerce (Basket) module, allowing unauthenticated remote attackers to modify object attributes.
Executive summary
A critical object injection vulnerability in the Drupal AlternativeCommerce (Basket) module allows unauthenticated attackers to achieve remote code execution and full system compromise.
Vulnerability
This vulnerability is caused by improper control of dynamically determined object attributes (CWE-915). It allows an unauthenticated, remote attacker to perform object injection, leading to total impact on confidentiality, integrity, and availability.
Business impact
The CVSS score of 9.8 reflects the extreme severity of this flaw, as it requires no authentication or user interaction to exploit. Successful exploitation could grant an attacker full control over the web application, resulting in unauthorized data access, modification of business transactions, and potential persistence within the hosting environment.
Remediation
Immediate Action: Update the Drupal AlternativeCommerce (Basket) module to version 2.1.17 or the latest available release as specified in the vendor advisory.
Proactive Monitoring: Monitor server logs for suspicious HTTP POST requests or patterns indicative of serialized object manipulation.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules specifically configured to detect and block common object injection payloads and unauthorized PHP serialization attempts.
Exploitation status
Public Exploit Available: No (unknown)
Analyst recommendation
Given the critical nature of this vulnerability and the potential for total system compromise, administrators should prioritize updating the affected module immediately. If an immediate update is not feasible, restrict access to the affected module or disable it entirely to prevent unauthorized exploitation.
More Drupal CVEs
Sources
Originally found and disclosed by Drew Webber (mcdruid), with Helena Zajika (helena zajika) (remediation developer), Drew Webber (mcdruid) (remediation developer), Greg Knaddison (greggles) (coordinator), Dave Long (longwave) (coordinator), Drew Webber (mcdruid) (coordinator), per the CVE Program record.