Observable Timing Discrepancy in Drupal Commerce CyberSource
CVE-2026-81159

Currently unrated

Key Information:

Vendor

Drupal

Vendor
CVE Published:
2 September 2026

What is CVE-2026-81159?

An Observable Timing Discrepancy vulnerability exists in Drupal Commerce CyberSource that can be exploited through Brute Force methods. This issue affects all versions from 0.0.0 to 1.10.0 and can lead to increased risk of unauthorized access. Users are advised to review their configurations and implement necessary updates to mitigate potential threats.

Affected Version(s)

Commerce CyberSource 0.0.0 < 1.10.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Brian Willows
Adrian M. (adrianandres)
Ryan Szrama (rszrama)
Vitaliy Marchuk (vmarchuk)
Neil Drumm (drumm)
Greg Knaddison (greggles)
Heine Deelstra (heine)
Juraj Nemec (poker10)
Jess (xjm)
.