PT-2026-44164 · Drupal · Basket

·

CVE-2026-9726

·

Published

2026-05-27

·

Updated

2026-08-06

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Drupal AlternativeCommerce (Basket) versions 0.0.0 through 2.1.17
Description Drupal AlternativeCommerce (Basket) contains an issue where user-supplied data is not sufficiently sanitized before being passed to the PHP unserialize() function. This allows for PHP Object Injection, a condition where an attacker can manipulate serialized objects to change the application's logic. If a viable gadget chain—a sequence of existing code fragments that can be executed during deserialization—is present in the site codebase or dependencies, this can lead to arbitrary PHP code execution.
Recommendations Update Drupal AlternativeCommerce (Basket) to version 2.1.17.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-9726
DRUPAL-CONTRIB-2026-038

Affected Products

Basket