Summary
CVE-2026-15089 is a critical security vulnerability in the Drupal Commerce guest registration contributed module, affecting all released versions. The Drupal security team issued advisory SA-CONTRIB-2026-079 classifying this as Critical — Unsupported, indicating the module maintainer has not addressed the issue and no patch will be provided. The CVE record assigns a CVSS 3.1 base score of 9.1 with a vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N; note that NVD’s independent assessment of this score is not yet complete.
Technical details
- Vulnerability type: Not publicly disclosed — the CVE description field is incomplete and neither the Drupal advisory nor any other confirmed source specifies the vulnerability class
- Exploit status: Theoretical — the Drupal security advisory confirms no public exploit code has been identified at the time of publication
- Attack surface: All configurations of the module are affected, per the Drupal security advisory
- CVSS impact: High confidentiality and integrity impact (C:H/I:H) with no availability impact (A:N), per the CVE record
- Scope: The module automates guest user account creation during or after Drupal Commerce checkout, making it directly accessible during the order flow on internet-facing storefronts
Affected software
- Drupal Commerce guest registration: All versions (
*.*) — including all releases supporting Drupal 8, Drupal 9, and Drupal 10 - The module is unmaintained and obsolete; its functionality has been incorporated into Drupal Commerce core from Drupal 10.x onward
Severity
CVSS 3.1 Base Score: 9.1 — Critical
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
⚠️ NVD’s independent CVSS assessment has not yet been published. The score above is as reported in the CVE record. NVD currently lists the record as "Awaiting Enrichment."
Mitigation and recommended actions
- No patch is available. The project is unsupported and the maintainer will not issue a fix.
- Immediate action: Uninstall the Commerce guest registration module from all Drupal installations. This is the explicit recommendation of the Drupal security team in SA-CONTRIB-2026-079.
- Migration path: Sites running Drupal Commerce on Drupal 10.x should migrate to the guest registration functionality now built natively into Drupal Commerce core.
- Drupal 8/9 sites: Evaluate exposure and uninstall the module immediately while planning a broader Commerce upgrade path.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

