CVE-2026-73475 PUBLISHED

Commerce PayPal - Moderately critical - Access bypass - SA-CONTRIB-2026-095

Assigner: drupal
Reserved: 12.08.2026 Published: 02.09.2026 Updated: 02.09.2026

Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing. This issue affects Commerce PayPal versions: from 0.0.0 to 1.12.0, from 2.0.0 to 2.1.3.

Product Status

Vendor Drupal
Product Commerce PayPal
Versions
  • affected from 0.0.0 to 1.12.0 (excl.)
  • affected from 2.0.0 to 2.1.3 (excl.)

Credits

  • Kimberley Massey (kimberleycgm) finder
  • Jonathan Sacksick (jsacksick) remediation developer
  • Kimberley Massey (kimberleycgm) remediation developer
  • Ryan Szrama (rszrama) remediation developer
  • Tom Ashe (tomtech) remediation developer
  • Swan Kalata (akalata) coordinator
  • Benji Fisher (benjifisher) coordinator
  • Neil Drumm (drumm) coordinator
  • Greg Knaddison (greggles) coordinator
  • Juraj Nemec (poker10) coordinator

References

Problem Types

  • CWE-863 Incorrect Authorization CWE

Impacts

  • CAPEC-87 Forceful Browsing