Commerce PayPal - Moderately critical - Access bypass - SA-CONTRIB-2026-095
View online: https://www.drupal.org/sa-contrib-2026-095 Project: Commerce PayPal [1] Date: 2026-August-12 Security risk: *Moderately critical* 12 ∕ 25 AC:Basic/A:None/CI:None/II:Some/E:Theoretical/TD:Default [2] Vulnerability: Access bypass Affected versions: <1.12.0 || >=2.1.0 <2.1.3 || 2.0.* CVE IDs: CVE-2026-73475 Description: This module enables you to pay for Commerce transactions using Paypal. The module doesn't sufficiently validate the transaction result in certain circumstances, allowing a malicious user to mark transactions placed without payment. This vulnerability only affects sites using the Payflow Link payment gateway. Solution: * If you use the Commerce Paypal module for Drupal, upgrade to Commerce Paypal 2.1.3 [3] or Commerce Paypal 8.x-1.12 [4] Reported By: * Kimberley Massey (kimberleycgm) [5] Fixed By: * Jonathan Sacksick (jsacksick) [6] * Kimberley Massey (kimberleycgm) [7] * Ryan Szrama (rszrama) [8] * Tom Ashe (tomtech) [9] Coordinated By: * Swan Kalata (akalata) [10] of the Drupal Security Team * Benji Fisher (benjifisher) [11] of the Drupal Security Team * Neil Drumm (drumm) [12] of the Drupal Security Team * Greg Knaddison (greggles) [13] of the Drupal Security Team * Juraj Nemec (poker10) [14] of the Drupal Security Team ------------------------------------------------------------------------------ Contribution record [15] [1] https://www.drupal.org/project/commerce_paypal [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/commerce_paypal/releases/2.1.3 [4] https://www.drupal.org/project/commerce_paypal/releases/8.x-1.12 [5] https://www.drupal.org/u/kimberleycgm [6] https://www.drupal.org/u/jsacksick [7] https://www.drupal.org/u/kimberleycgm [8] https://www.drupal.org/u/rszrama [9] https://www.drupal.org/u/tomtech [10] https://www.drupal.org/u/akalata [11] https://www.drupal.org/u/benjifisher [12] https://www.drupal.org/u/drumm [13] https://www.drupal.org/u/greggles [14] https://www.drupal.org/u/poker10 [15] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal....
participants (1)
-
security-news@drupal.org