Description
Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing. This issue affects Commerce PayPal versions: from 0.0.0 to 1.12.0, from 2.0.0 to 2.1.3.
Published: 2026-09-02
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access through incorrect authorization
Action: Apply Patch
AI Analysis

Impact

An incorrect authorization flaw in Drupal Commerce PayPal permits forceful browsing, letting an attacker access pages or functions that should be restricted to legitimate users. The vulnerability is a missing or incorrect authorization check, identified as CWE-863. Successful exploitation can allow the attacker to retrieve sensitive order information, modify cart details, or perform privileged operations without proper authentication.

Affected Systems

Drupal Commerce PayPal from version 0.0.0 to 1.12.0 and from 2.0.0 to 2.1.3 are affected. Any site running these versions without applying the vendor’s recent fix is at risk.

Risk and Exploitability

The flaw allows an attacker to bypass normal authorization checks, presenting an opportunity to access sensitive commerce resources. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is through web requests or API calls that exploit the missing authorization guard. An attacker would need only a web browser or a script to attempt access to protected resources, making exploitation relatively straightforward where the module is deployed. The CVSS score of 9.1 indicates a critical severity.

Generated by OpenCVE AI on September 3, 2026 at 10:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade or patch Commerce PayPal to the latest version that contains the vendor’s fix for the authorization issue
  • Re-review module role permissions and ensure all restricted routes require proper authentication
  • Enable detailed logging for access attempts and monitor logs for anomalous requests against protected commerce endpoints

Generated by OpenCVE AI on September 3, 2026 at 10:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Tue, 08 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Centarro
Centarro commerce Paypal
CPEs cpe:2.3:a:centarro:commerce_paypal:*:*:*:*:*:drupal:*:*
Vendors & Products Centarro
Centarro commerce Paypal

Thu, 03 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Wed, 02 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Drupal
Drupal commerce Paypal
Vendors & Products Drupal
Drupal commerce Paypal

Wed, 02 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing. This issue affects Commerce PayPal versions: from 0.0.0 to 1.12.0, from 2.0.0 to 2.1.3.
Title Commerce PayPal - Moderately critical - Access bypass - SA-CONTRIB-2026-095
Weaknesses CWE-863
References

Subscriptions

Centarro Commerce Paypal
Drupal Commerce Paypal
cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-09-02T18:33:12.159Z

Reserved: 2026-08-12T17:21:18.776Z

Link: CVE-2026-73475

cve-icon Vulnrichment

Updated: 2026-09-02T18:32:54.786Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-02T13:18:08.300

Modified: 2026-09-08T14:54:13.920

Link: CVE-2026-73475

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T10:15:05Z

Weaknesses