CVE-2026-73475: Commerce PayPal - Moderately critical - Access bypass - SA-CONTRIB-2026-095
Published Sep 2, 2026
·Updated
Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing. This issue affects Commerce PayPal versions: from 0.0.0 to 1.12.0, from 2.0.0 to 2.1.3.
Affected Software
1 affected component
Drupal Commerce PayPal>=0.0.0<=1.12.0, >=2.0.0<=2.1.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal-commerce-paypalto a version that resolves this vulnerability.Fixed in 1.12.0Patch SA-CONTRIB-2026-095 - Upgrade
Upgrade
drupal-commerce-paypalto a version that resolves this vulnerability.Fixed in 2.1.3Patch SA-CONTRIB-2026-095
Event History
Sep 2, 2026
CVE Published
via MITRE·12:32 PM
Data Sourced
via MITRE·12:32 PM
DescriptionWeakness