Intel

AIKIDO-2026-929609

drupal/commerce_paypal is vulnerable to Access Bypass

Access BypassCVE-2026-73475 Published 4 days ago

55

Medium Risk

This Affects:

PHPdrupal/commerce_paypal
0.0.1 - 1.11.0
Fixed in 1.12.0
2.0.0 - 2.1.2
Fixed in 2.1.3
Are you affected? Scan for Free

TL;DR

The Commerce PayPal module for Drupal does not sufficiently validate Payflow Link transaction results in certain circumstances, allowing a malicious user to mark orders as paid without completing payment. This issue only affects sites that use the Payflow Link payment gateway.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and your site uses the Payflow Link payment gateway.

Background info

drupal/commerce_paypal is vulnerable to Access Bypass in versions 0.0.1 - 1.11.0 and 2.0.0 - 2.1.2.

How to fix this

Upgrade the drupal/commerce_paypal library to the patch version.