Executive brief
Drupal's Commerce Decoupled Checkout module provides REST endpoints for remote order creation in headless e-commerce deployments. The module fails to properly validate order data submitted through these endpoints, allowing attackers to set unauthorized order properties that could lead to order manipulation, data integrity issues, or privilege escalation in the checkout process.
Technical details
The REST order creation endpoint in Commerce Decoupled Checkout versions 1.0.0 through 1.7.x lacks sufficient input sanitization, permitting unsafe order properties to be set directly. An attacker with network access to the endpoint can submit order data containing fields outside the default allowlist (type, email, store, order_items), resulting in unauthorized modification of order state. The fix restricts accepted fields to an explicit allowlist and requires administrators to explicitly enable any custom order fields at /admin/commerce/config/decoupled-checkout.
Affected products
- Drupal Commerce Decoupled Checkout >=1.0.0 <1.8.0
Timeline
- 2026-09-23: disclosed
- 2026-09-23: patched: Fixed in version 1.8.0