DIRAS TAKE
Treat this as urgent because the flaw requires no login and allows unauthenticated access; prioritize patching or mitigation immediately for any internet-facing Drupal sites running the module.
What is CVE-2026-73475?
Unauthenticated remote attackers can use forceful browsing to access or act on Commerce PayPal resources in Drupal. CVE-2026-73475 is an improper-authorization flaw that affects Commerce PayPal 1.x before 1.12.0 and 2.x from 2.0.0 before 2.1.3; an attacker only needs network access and does not require a valid account or user interaction to exploit it.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Which versions of Drupal Commerce PayPal are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 1.x | before 1.12.0 | 1.12.0 |
| 2.x | 2.0.0 – before 2.1.3 | 2.1.3 |
Is CVE-2026-73475 being exploited?
There are no public reports of exploitation or public exploit code as of 2026-09-30.
How to fix CVE-2026-73475
- Upgrade Commerce PayPal to 1.12.0 or 2.1.3 (the fixed releases).
- If you cannot upgrade immediately, restrict access to the module endpoints from untrusted networks and block direct public access.
- Monitor web and application logs for unusual requests to Commerce PayPal endpoints and for unauthorized order or payment activity.
- Apply any additional vendor guidance from the module maintainer and review access controls for Commerce PayPal resources.
Frequently asked questions
Is CVE-2026-73475 being actively exploited?
There are no public reports of active exploitation of CVE-2026-73475 as of 2026-09-30.
Which Commerce PayPal versions are affected by CVE-2026-73475?
Commerce PayPal 1.x versions before 1.12.0 and 2.x versions from 2.0.0 up to but not including 2.1.3 are affected.
Is there a patch for CVE-2026-73475?
Yes, fixed releases are available: update to Commerce PayPal 1.12.0 or 2.1.3.
Does CVE-2026-73475 require authentication?
No, the vulnerability does not require authentication; an attacker can exploit it without a valid account or user interaction.
References
- nvd.nist.gov/vuln/detail/CVE-2026-73475
- cve.org/CVERecord?id=CVE-2026-73475
- drupal.org/sa-contrib-2026-095
- All Drupal CVEs on CVE Radar
- CVEs published in September 2026