Incorrect Authorization in Drupal Commerce PayPal
CVE-2026-73475
Currently unrated
What is CVE-2026-73475?
An incorrect authorization vulnerability in Drupal Commerce PayPal has been identified, enabling potential attackers to engage in forceful browsing. This issue affects users of Commerce PayPal plugin versions ranging from 0.0.0 to 1.12.0 and 2.0.0 to 2.1.3, allowing unauthorized access to sensitive functionalities. Users are advised to update to the latest version to mitigate the risk associated with this vulnerability.
Affected Version(s)
Commerce PayPal 0.0.0 < 1.12.0
Commerce PayPal 2.0.0 < 2.1.3
References
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Kimberley Massey (kimberleycgm)
Jonathan Sacksick (jsacksick)
Kimberley Massey (kimberleycgm)
Ryan Szrama (rszrama)
Tom Ashe (tomtech)
Swan Kalata (akalata)
Benji Fisher (benjifisher)
Neil Drumm (drumm)
Greg Knaddison (greggles)
Juraj Nemec (poker10)
