• PATCH AVAILABLE

CVE-2026-73475: improper authorization in Drupal Commerce PayPal

Unauthenticated remote attackers can use forceful browsing to access or act on Commerce PayPal resources in Drupal. CVE-2026-73475 is an improper-authorization flaw that affects Commerce PayPal 1.x before 1.12.0 and 2.x from 2.0.0 before 2.1.3; an attacker only needs network access and does not require a valid account or user interaction to exploit it.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.1CRITICAL
EPSS
0.00404
CWE
CWE-863
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Treat this as urgent because the flaw requires no login and allows unauthenticated access; prioritize patching or mitigation immediately for any internet-facing Drupal sites running the module.

What is CVE-2026-73475?

Unauthenticated remote attackers can use forceful browsing to access or act on Commerce PayPal resources in Drupal. CVE-2026-73475 is an improper-authorization flaw that affects Commerce PayPal 1.x before 1.12.0 and 2.x from 2.0.0 before 2.1.3; an attacker only needs network access and does not require a valid account or user interaction to exploit it.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Which versions of Drupal Commerce PayPal are affected?

BRANCHAFFECTEDFIXED
1.xbefore 1.12.01.12.0
2.x2.0.0 – before 2.1.32.1.3

Is CVE-2026-73475 being exploited?

There are no public reports of exploitation or public exploit code as of 2026-09-30.

How to fix CVE-2026-73475

  1. Upgrade Commerce PayPal to 1.12.0 or 2.1.3 (the fixed releases).
  2. If you cannot upgrade immediately, restrict access to the module endpoints from untrusted networks and block direct public access.
  3. Monitor web and application logs for unusual requests to Commerce PayPal endpoints and for unauthorized order or payment activity.
  4. Apply any additional vendor guidance from the module maintainer and review access controls for Commerce PayPal resources.

Frequently asked questions

Is CVE-2026-73475 being actively exploited?

There are no public reports of active exploitation of CVE-2026-73475 as of 2026-09-30.

Which Commerce PayPal versions are affected by CVE-2026-73475?

Commerce PayPal 1.x versions before 1.12.0 and 2.x versions from 2.0.0 up to but not including 2.1.3 are affected.

Is there a patch for CVE-2026-73475?

Yes, fixed releases are available: update to Commerce PayPal 1.12.0 or 2.1.3.

Does CVE-2026-73475 require authentication?

No, the vulnerability does not require authentication; an attacker can exploit it without a valid account or user interaction.

References