CVE-2026-9726
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal AlternativeCommerce (Basket) allows Object Injection. This issue affects Drupal AlternativeCommerce (Basket) versions: from 0.0.0 to 2.1.17.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.drupalcode.org/project/basket, https://www.drupal.org/project/basket, https://www.drupal.org/sa-contrib-2026-038, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/9xxx/CVE-2026-9726.json, https://nvd.nist.gov/vuln/detail/CVE-2026-9726