Description
Observable Timing Discrepancy vulnerability in Drupal Commerce CyberSource allows Brute Force. This issue affects Commerce CyberSource versions: from 0.0.0 to 1.10.0.
Published: 2026-09-02
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Drupal Commerce CyberSource is an observable timing discrepancy caused by insufficient input validation. It allows an attacker to perform brute‑force attempts against authentication or transaction validation routines, potentially elevating privileges or executing fraudulent operations. This weakness is classified as CWE‑208, which concerns improper input validation that can be exploited through timing attacks.

Affected Systems

Drupal Commerce CyberSource is affected. All versions from 0.0.0 up to and including 1.10.0 contain the flaw. No specific sub‑versions or patch releases are listed as mitigated.

Risk and Exploitability

The EPSS score is not available and the vulnerability is not currently listed in CISA KEV, indicating no known active exploitation at the time of disclosure. However, the flaw permits brute‑force attacks by measuring response times, making it exploitable if an attacker can send repeated requests to the affected endpoints, which is inferred to be the web or API interfaces of the module. The lack of severity metrics in the data does not diminish the potential impact, as the flaw could enable unauthorized access or financial fraud.

Generated by OpenCVE AI on September 2, 2026 at 13:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Drupal Commerce CyberSource to a non‑vulnerable release that removes the timing discrepancy flaw.
  • Apply any security patches or security releases published by the Drupal community or the module maintainer to address the input validation issue.
  • Implement rate limiting or brute‑force protection on Commerce CyberSource endpoints to reduce the effectiveness of timing attacks.
  • Monitor logs for abnormal request patterns or response time variations that may indicate attempts to exploit the timing discrepancy.

Generated by OpenCVE AI on September 2, 2026 at 13:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 02 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Observable Timing Discrepancy vulnerability in Drupal Commerce CyberSource allows Brute Force. This issue affects Commerce CyberSource versions: from 0.0.0 to 1.10.0.
Title Commerce CyberSource - Moderately critical - Insufficient input validation - SA-CONTRIB-2026-106
Weaknesses CWE-208
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-09-02T12:32:12.560Z

Reserved: 2026-08-26T16:19:41.862Z

Link: CVE-2026-81159

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-02T13:18:11.653

Modified: 2026-09-02T13:53:45.597

Link: CVE-2026-81159

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T13:30:05Z

Weaknesses
  • CWE-208

    Observable Timing Discrepancy