Commerce CyberSource - Moderately critical - Insufficient input validation - SA-CONTRIB-2026-106
View online: https://www.drupal.org/sa-contrib-2026-106 Project: Commerce CyberSource [1] Date: 2026-August-26 Security risk: *Moderately critical* 11 ∕ 25 AC:Complex/A:None/CI:None/II:Some/E:Theoretical/TD:Default [2] Vulnerability: Insufficient input validation Affected versions: <1.10.0 CVE IDs: CVE-2026-81159 Description: This module integrates Drupal Commerce with the CyberSource payment gateway. The module does not correctly verify the integrity of data returned by the payment provider. A timing attack could allow an attacker to trick the site into registering that payment has been received even if it hasn't. This issue only affects the Secure Acceptance Hosted Checkout gateway integration. Solution: Install the latest version: * If you use the Commerce CyberSource module, upgrade to Commerce CyberSource 8.x-1.10 [3]. Reported By: * Brian Willows [4] Fixed By: * Adrian M. (adrianandres) [5] * Ryan Szrama (rszrama) [6] * Vitaliy Marchuk (vmarchuk) [7] Coordinated By: * Neil Drumm (drumm) [8] of the Drupal Security Team * Greg Knaddison (greggles) [9] of the Drupal Security Team * Heine Deelstra (heine) [10] of the Drupal Security Team * Juraj Nemec (poker10) [11] of the Drupal Security Team * Jess (xjm) [12] of the Drupal Security Team ------------------------------------------------------------------------------ Contribution record [13] [1] https://www.drupal.org/project/commerce_cybersource [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/commerce_cybersource/releases/8.x-1.10 [4] https://www.drupal.org/u/brian-willows [5] https://www.drupal.org/u/adrianandres [6] https://www.drupal.org/u/rszrama [7] https://www.drupal.org/u/vmarchuk [8] https://www.drupal.org/u/drumm [9] https://www.drupal.org/u/greggles [10] https://www.drupal.org/u/heine [11] https://www.drupal.org/u/poker10 [12] https://www.drupal.org/u/xjm [13] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal....
participants (1)
-
security-news@drupal.org