SA-CONTRIB-2026-095: Critical severity drupal/commerce_paypal vulnerability
This module enables you to pay for Commerce transactions using Paypal. The module doesn't sufficiently validate the transaction result in certain circumstances, allowing a malicious user to mark transactions placed without payment. This vulnerability only affects sites using the Payflow Link payment gateway.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/commerce_paypalto a version that resolves this vulnerability.Fixed in 2.1.3Fixed in 8.x-1.12
Event History
Frequently Asked Questions
What is the severity of SA-CONTRIB-2026-095?
The severity of SA-CONTRIB-2026-095 is rated as critical with a score of 9.
What does SA-CONTRIB-2026-095 affect?
SA-CONTRIB-2026-095 affects sites using the Drupal Commerce PayPal module specifically with Payflow Link payment processing.
How do I fix SA-CONTRIB-2026-095?
To fix SA-CONTRIB-2026-095, update the Drupal Commerce PayPal module to the latest version provided by the maintainers.
What risks does SA-CONTRIB-2026-095 pose to my site?
SA-CONTRIB-2026-095 allows a malicious user to mark transactions as complete without actual payment, potentially leading to financial losses.
When was SA-CONTRIB-2026-095 published?
SA-CONTRIB-2026-095 was published on August 12, 2026.