CVE-2026-73475

Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing. This issue affects Commerce PayPal versions: from 0.0.0 to 1.12.0, from 2.0.0 to 2.1.3.
References
Link Resource
https://www.drupal.org/sa-contrib-2026-095 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:centarro:commerce_paypal:*:*:*:*:*:drupal:*:*
cpe:2.3:a:centarro:commerce_paypal:*:*:*:*:*:drupal:*:*

History

No history.

Information

Published : 2026-09-02 13:18

Updated : 2026-09-08 14:54


NVD link : CVE-2026-73475

Mitre link : CVE-2026-73475

CVE.ORG link : CVE-2026-73475


JSON object : View

Products Affected

centarro

  • commerce_paypal
CWE
CWE-863

Incorrect Authorization