SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-9726

CRITICAL · CVSS 9.8 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

Drupal AlternativeCommerce (Basket) versions 0.0.0 to 2.1.17 are vulnerable to an object injection flaw due to improperly controlled modifications of dynamically-determined object attributes. This critical vulnerability can lead to unauthorized access and manipulation of object data, potentially compromising the integrity of the application. Organizations using affected versions should prioritize immediate remediation to mitigate risks of exploitation.

CVE
CVE-2026-9726
Severity
CRITICAL
CVSS
9.8
EPSS
0.31%

Original NVD Description

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal AlternativeCommerce (Basket) allows Object Injection. This issue affects Drupal AlternativeCommerce (Basket) versions: from 0.0.0 to 2.1.17.