Incorrect Authorization in Drupal Commerce PayPal
CVE-2026-73475

Currently unrated

Key Information:

Vendor

Drupal

Vendor
CVE Published:
2 September 2026

What is CVE-2026-73475?

An incorrect authorization vulnerability in Drupal Commerce PayPal has been identified, enabling potential attackers to engage in forceful browsing. This issue affects users of Commerce PayPal plugin versions ranging from 0.0.0 to 1.12.0 and 2.0.0 to 2.1.3, allowing unauthorized access to sensitive functionalities. Users are advised to update to the latest version to mitigate the risk associated with this vulnerability.

Affected Version(s)

Commerce PayPal 0.0.0 < 1.12.0

Commerce PayPal 2.0.0 < 2.1.3

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kimberley Massey (kimberleycgm)
Jonathan Sacksick (jsacksick)
Kimberley Massey (kimberleycgm)
Ryan Szrama (rszrama)
Tom Ashe (tomtech)
Swan Kalata (akalata)
Benji Fisher (benjifisher)
Neil Drumm (drumm)
Greg Knaddison (greggles)
Juraj Nemec (poker10)
.