Description
Incorrect Authorization vulnerability in Drupal Commerce Realex / Global Payments allows Forceful Browsing. This issue affects Commerce Realex / Global Payments versions: from 0.0.0 to 3.0.2.
Published: 2026-07-10
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an incorrect authorization flaw that allows forceful browsing of protected resources in the Drupal Commerce Realex / Global Payments module. Attackers can access payment processing pages or transaction data that should be restricted, enabling unauthorized viewing weakness is a classic access control failure classified as CWE‑863.

Affected Systems

Drupal sites using the Commerce Realex / Global Payments module, all released versions from 0.0.0 up to and including 3.0.2, are affected.

Risk and Exploitability

The CVSS score of 4.8 indicates moderate severity, but the EPSS of <1% suggests the likelihood of exploitation is very low. The vulnerability is not listed in CISA KEV. Based on the description, it is inferred that attackers could potentially target the web interface by crafting URLs to bypass authorization checks. While no active exploitation reports are known, sites that expose payment processing pages without proper role restrictions face significant risk.

Generated by OpenCVE AI on July 31, 2026 at 12:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Audit the role permissions for all Commerce Realex / Global Payments routes and limit access to authorized administrative users.
  • Disable any legacy or unused authentication methods that could expose payment processing functionality, and enforce strict permission checks on every route.
  • Check for an official patch or update from Drupal or Commerce Realex / Global Payments, and apply it when available.

Generated by OpenCVE AI on July 31, 2026 at 12:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 13 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Drupal
Drupal commerce Realex / Global Payments
Vendors & Products Drupal
Drupal commerce Realex / Global Payments

Fri, 10 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization vulnerability in Drupal Commerce Realex / Global Payments allows Forceful Browsing. This issue affects Commerce Realex / Global Payments versions: from 0.0.0 to 3.0.2.
Title Commerce Realex / Global Payments - Moderately critical - Access Bypass - SA-CONTRIB-2026-058
Weaknesses CWE-863
References

Subscriptions

Drupal Commerce Realex / Global Payments
cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-07-13T18:00:23.950Z

Reserved: 2026-06-24T18:00:11.427Z

Link: CVE-2026-13238

cve-icon Vulnrichment

Updated: 2026-07-13T16:27:41.919Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T13:00:10Z

Weaknesses