Security Vulnerability in Drupal Commerce Affecting Guest Registration
CVE-2026-15089

9.1CRITICAL

Key Information:

Vendor

Drupal

Vendor
CVE Published:
10 July 2026

What is CVE-2026-15089?

A security vulnerability in Drupal Commerce affects the guest registration process, potentially allowing unauthorized access or exploitation. This flaw impacts all versions of the guest registration component in Drupal Commerce. Users and administrators are encouraged to examine their current implementations and update to the latest secure versions to mitigate risks. More details can be found in the Drupal security advisory.

Affected Version(s)

Commerce guest registration *.*

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.