← Terug naar overzicht

CVE-2026-73475 describes an Incorrect Authorization vulnerability in the Drupal Commerce PayPal module. The flaw allows attackers to exploit Forceful Browsing, potentially accessing restricted resources without proper authorization. The vulnerability affects two version ranges: from 0.0.0 to 1.12.0 and from 2.0.0 to 2.1.3. This type of vulnerability can lead to unauthorized access to payment-related pages or order data within Drupal-based e-commerce sites. The issue has been documented by the Drupal security team via security advisory sa-contrib-2026-095. Organizations using the affected versions of Commerce PayPal should apply patches or updates promptly. The vulnerability is currently awaiting full analysis on the NVD.

Affected products

  • Drupal Commerce PayPal 0.0.0-1.12.0
  • Drupal Commerce PayPal 2.0.0-2.1.3

Related CVE's

  • CVE-2026-73475

Categories

  • Enterprise Applications
  • Identity & Access
  • Web Technologies