Junglewise Threat Intelligence

CVE-2026-96378: Drupal Commerce Decoupled Checkout access bypass in REST endpoint

CVE-2026-96378 · Severity: info · Published 2026-09-23

Vendors: Drupal, Packagist:Https://Packages.Drupal.Org/8.

Executive brief

Drupal's Commerce Decoupled Checkout module provides REST endpoints for remote order creation in headless e-commerce deployments. The module fails to properly validate order data submitted through these endpoints, allowing attackers to set unauthorized order properties that could lead to order manipulation, data integrity issues, or privilege escalation in the checkout process.

Technical details

The REST order creation endpoint in Commerce Decoupled Checkout versions 1.0.0 through 1.7.x lacks sufficient input sanitization, permitting unsafe order properties to be set directly. An attacker with network access to the endpoint can submit order data containing fields outside the default allowlist (type, email, store, order_items), resulting in unauthorized modification of order state. The fix restricts accepted fields to an explicit allowlist and requires administrators to explicitly enable any custom order fields at /admin/commerce/config/decoupled-checkout.

Affected products

  • Drupal Commerce Decoupled Checkout >=1.0.0 <1.8.0

Timeline

  • 2026-09-23: disclosed
  • 2026-09-23: patched: Fixed in version 1.8.0

References