Description
Vulnerability in Drupal Commerce Elavon. This issue affects Commerce Elavon versions: *.*.
Published: 2026-08-25
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The reported issue is identified as a critical vulnerability in the Drupal Commerce Elavon module. The description states that all versions are affected, implying an unspecified flaw that could allow an attacker to manipulate the module’s behavior. Because the product is listed as unsupported, no patch is currently available, and the flaw could lead to unauthorized payment actions or data exposure. The core weakness appears to be related to improper handling of payment requests, although the precise technical details are not disclosed in the advisory.

Affected Systems

The affected product is Drupal Commerce Elavon. Every documented version of the module, indicated by the pattern *.*., is susceptible. Organization using Drupal Commerce Elavon should check their installed version against the vendor’s product list even though no specific version numbers are supplied.

Risk and Exploitability

The EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog, but the unsupported status means that no public fix exists at present. Exploit potential remains high for a system that can be reached over the web and does not have additional controls in place. With no known confirmations of exploitation, the likelihood of attack is uncertain, but the lack of remediation creates a significant residual risk that an attacker may discover or develop a method to exploit the flaw.

Generated by OpenCVE AI on August 26, 2026 at 01:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Review the latest release notes for Drupal Commerce Elavon to confirm whether a security fix has been issued.
  • When a patched version or vendor‑supplied update becomes available, apply it immediately to eliminate the risk.
  • Because the module is unsupported, consider decommissioning or replacing it with a supported e‑commerce solution while monitoring for new advisories and monitoring network traffic for abnormal payment activity.

Generated by OpenCVE AI on August 26, 2026 at 01:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 26 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Tue, 25 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in Drupal Commerce Elavon. This issue affects Commerce Elavon versions: *.*.
Title Commerce Elavon - Critical - Unsupported - SA-CONTRIB-2026-084
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-08-25T22:22:02.591Z

Reserved: 2026-07-22T17:06:43.440Z

Link: CVE-2026-16641

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T23:16:56.900

Modified: 2026-08-25T23:16:56.900

Link: CVE-2026-16641

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T01:45:03Z

Weaknesses
  • CWE-20

    Improper Input Validation