Critical severity9.8NVD Advisory· Published Jul 10, 2026· Updated Aug 6, 2026
CVE-2026-9726
CVE-2026-9726
Description
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal AlternativeCommerce (Basket) allows Object Injection. This issue affects Drupal AlternativeCommerce (Basket) versions: from 0.0.0 to 2.1.17.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- cpe:2.3:a:alternativecommerce:alternativecommerce:*:*:*:*:*:drupal:*:*Range: <2.1.17
- Range: 0.0.0 - 2.1.17
Patches
Vulnerability mechanics
References
1- www.drupal.org/sa-contrib-2026-038nvdVendor Advisory
News mentions
0No linked articles in our index yet.