CVE-2026-16641: pre-auth input validation in Drupal Commerce Elavon

An attacker can remotely and without authentication exploit an input validation flaw in the Drupal Commerce Elavon module, tracked as CVE-2026-16641, to cause high-impact compromise of affected sites. The vendor reports all Commerce Elavon versions are affected (*.*). Exploitation requires network access to the vulnerable module and does not require a valid account or user interaction, giving attackers direct remote access to trigger the issue.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.0029
CWE
CWE-20
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: this is an unauthenticated, remotely reachable vulnerability affecting all Commerce Elavon releases, so immediately limit exposure and prepare to apply vendor guidance once a fix is released.

What is CVE-2026-16641?

An attacker can remotely and without authentication exploit an input validation flaw in the Drupal Commerce Elavon module, tracked as CVE-2026-16641, to cause high-impact compromise of affected sites. The vendor reports all Commerce Elavon versions are affected (*.*). Exploitation requires network access to the vulnerable module and does not require a valid account or user interaction, giving attackers direct remote access to trigger the issue.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Drupal Commerce Elavon are affected?

BRANCHAFFECTEDFIXED
Commerce Elavon*.*

Is CVE-2026-16641 being exploited?

There are no public reports of exploitation or public exploit code as of 2026-09-29.

How to fix CVE-2026-16641

  1. Restrict network access to Commerce Elavon endpoints (block or firewall to internal-only where possible).
  2. Monitor logs and alerts for unusual requests targeting the Commerce Elavon module and related endpoints.
  3. Follow vendor guidance and apply a vendor-supplied patch or update immediately when one is released.
  4. Implement virtual patching or WAF rules to block malformed input patterns that target the module.

Frequently asked questions

Is CVE-2026-16641 being actively exploited?

There are no public reports of active exploitation or public exploit code as of 2026-09-29.

Which Commerce Elavon versions are affected by CVE-2026-16641?

All Commerce Elavon versions are affected; the vendor lists the affected range as *.*.

Is there a patch for CVE-2026-16641?

No patch is available as of 2026-09-29; follow the vendor's guidance and apply mitigations until an official fix is released.

Does CVE-2026-16641 require authentication?

No; the vulnerability can be triggered without authentication and only requires network access to the vulnerable module.

References