ZeroHour

CVE-2026-73475

large

Incorrect Authorization (Forceful Browsing) in Drupal Commerce PayPal

CVSS 3.1
9.1 critical
EPSS
<1%p14
Published
()
Modified
AI analysis

Commerce PayPal, the PayPal payment-gateway integration module for Drupal Commerce maintained by Centarro, contains an incorrect authorization flaw (CWE-863) that Drupal classifies as Forceful Browsing. Because the module fails to correctly enforce its access checks, an unauthenticated remote attacker can request protected routes or endpoints handled by the module and reach content or functionality they should not be able to access; the CVSS vector (network vector, no privileges, no user interaction, high confidentiality and integrity impact, no availability impact) indicates the attacker can both read sensitive data and modify data or state. Every published version of the module is affected, since both the 1.x line through 1.12.0 and the 2.x line through 2.1.3 fall within the affected ranges, so any Drupal site running Commerce PayPal is exposed. There is currently no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns a low 0.2% probability of exploitation within 30 days, so no exploitation in the wild has been confirmed.

What to do: Update Commerce PayPal to the first release published after 1.12.0 on the 1.x branch or after 2.1.3 on the 2.x branch, distributed via drupal.org. Until patched, review web-server logs for unauthenticated requests to the module's routes and audit recent PayPal orders and transactions for unauthorized access or changes. Take care that any network-level mitigation does not block PayPal's server-to-server callbacks (webhooks/IPN), which must remain publicly reachable.

Affected
Centarro Commerce PayPal0.0.0 through 1.12.0 (entire 1.x line up to and including 1.12.0)
Centarro Commerce PayPal2.0.0 through 2.1.3 (entire 2.x line up to and including 2.1.3)
Estimated exposure
large≈10,000+ Drupal sites — Drupal.org project usage statistics report on the order of ten thousand reported installations for the Commerce PayPal module, and because every published release in both branches is affected, effectively all active users of the module are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing. This issue affects Commerce PayPal versions: from 0.0.0 to 1.12.0, from 2.0.0 to 2.1.3.

Vendors
centarro
Products
commerce paypal
Ecosystems
Drupal
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.