Junglewise Threat Intelligence

CVE-2026-15089: Drupal Commerce guest registration unpatched security vulnerability

CVE-2026-15089 · Severity: info · CVSS 7.2 · Published 2026-07-10

Vendors: Drupal, Packagist:Https://Packages.Drupal.Org/8.

Executive brief

The Drupal Commerce guest registration module, which automatically creates user accounts for customers during checkout, has been marked as unsupported due to an unpatched security vulnerability. This module is used to streamline the shopping experience by converting guest shoppers into registered users. Because the maintainer has not addressed the security flaw, the Drupal Security Team recommends uninstalling the module immediately to prevent potential unauthorized access or site compromise.

Technical details

The Drupal Commerce guest registration module is subject to a critical security vulnerability that remains unpatched. The module is designed to automatically create user accounts and map orders to existing users based on email addresses during the guest checkout process. The Drupal Security Team has issued a 'Critical' risk rating (16/25) for the project and subsequently marked it as unsupported due to the maintainer's failure to resolve the issue. While specific exploit details were not disclosed to protect remaining users, the vulnerability likely impacts the integrity and confidentiality of user accounts or order data. Users are advised to uninstall the module and migrate to the native account registration features available in Drupal Commerce Core.

Affected products

  • Drupal Commerce guest registration *.*

Timeline

  • 2026-07-08: advisory: Drupal Security Team marks project unsupported via SA-CONTRIB-2026-079
  • 2026-07-10: disclosed: CVE-2026-15089 published

References