Description
Vulnerability in Drupal Commerce Elavon. This issue affects Commerce Elavon versions: *.*.
Published: 2026-08-25
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Potential for unauthorized access or compromise of Drupal Commerce Elavon payment workflows
Action: Assess Impact
AI Analysis

Impact

The advisory describes a critical flaw in the Drupal Commerce Elavon module that affects all documented versions (*.*.). The CVE indicates an unspecified weakness that could allow manipulation of payment transaction processing. The precise technical details are not disclosed, but based on the description it is inferred that the vulnerability could enable unauthorized payment actions or expose sensitive transaction information. The weakness is categorized as CWE-20, indicating improper input validation or unchecked data handling.

Affected Systems

The affected product is Drupal Commerce Elavon. Every documented version of the module, indicated by the pattern *.*., is susceptible. Organization using Drupal Commerce Elavon should check their installed version against the vendor’s product list even though no specific version numbers are supplied.

Risk and Exploitability

CVSS score 9.8 signals critical severity. EPSS score < 1% suggests a low exploitation probability at present. The vulnerability is not listed in the CISA KEV catalog. Based on the lack of confirmed exploitation, it is inferred that the likelihood of real-world attacks remains uncertain; however, the lack of a publicly disclosed fix or patch status means the residual risk persists. The likely attack vector is over the network (web interface), but this is inferred from the context of a payment module and not explicitly stated in the advisory. Exploit potential remains high if the module is reachable over the web.

Generated by OpenCVE AI on August 26, 2026 at 22:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Review the latest release notes for Drupal Commerce Elavon to confirm whether a security fix has been issued.
  • When a patched version or vendor‑supplied update becomes available, apply it immediately to eliminate the risk.
  • Monitor for new advisories and network traffic for abnormal payment activity.

Generated by OpenCVE AI on August 26, 2026 at 22:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 26 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Tue, 25 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in Drupal Commerce Elavon. This issue affects Commerce Elavon versions: *.*.
Title Commerce Elavon - Critical - Unsupported - SA-CONTRIB-2026-084
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-08-26T18:09:19.251Z

Reserved: 2026-07-22T17:06:43.440Z

Link: CVE-2026-16641

cve-icon Vulnrichment

Updated: 2026-08-26T18:08:15.663Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-25T23:16:56.900

Modified: 2026-08-28T15:29:44.967

Link: CVE-2026-16641

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T22:15:05Z

Weaknesses
  • CWE-20

    Improper Input Validation