CVE-2026-73475

9.1

Drupal · Commerce PayPal

An incorrect authorization vulnerability in the Drupal Commerce PayPal module allows unauthenticated attackers to perform forceful browsing, potentially leading to unauthorized data access or modification.

Executive summary

A critical authorization bypass vulnerability in the Drupal Commerce PayPal module allows unauthenticated remote attackers to manipulate sensitive payment configurations and order data.

Vulnerability

The module fails to correctly enforce authorization checks (CWE-863), enabling unauthenticated users to access restricted administrative functions through forceful browsing. This vulnerability permits attackers to interact with payment gateway settings and order information without requiring valid credentials.

Business impact

The identified vulnerability carries a CVSS score of 9.1, reflecting its critical severity due to the lack of required authentication and the potential for total impact on data confidentiality and integrity. Successful exploitation could allow unauthorized actors to intercept payment details, manipulate transaction flows, or access sensitive customer order data, leading to severe financial loss, regulatory non-compliance, and significant reputational damage.

Remediation

Immediate Action: Update the Drupal Commerce PayPal module to the latest patched version as specified in the official vendor advisory at https://www.drupal.org/sa-contrib-2026-095.

Proactive Monitoring: Review web server and Drupal access logs for suspicious requests targeting payment configuration paths or unusual administrative activity from unauthorized IP addresses.

Compensating Controls: Implement strict Web Application Firewall (WAF) rules to block unauthorized requests to the identified administrative endpoints associated with the Commerce PayPal module until the patch is deployed.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical nature of this authorization flaw and its potential for direct impact on financial transaction integrity, immediate remediation is required. Administrators must prioritize applying the vendor provided patch to all affected Drupal installations to prevent unauthorized access to sensitive payment and customer data.

More Drupal CVEs

Sources

Originally found and disclosed by Kimberley Massey (kimberleycgm), with Jonathan Sacksick (jsacksick) (remediation developer), Kimberley Massey (kimberleycgm) (remediation developer), Ryan Szrama (rszrama) (remediation developer), Tom Ashe (tomtech) (remediation developer), Swan Kalata (akalata) (coordinator), per the CVE Program record.