SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-73475

CRITICAL · CVSS 9.1 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Drupal Commerce PayPal is susceptible to an incorrect authorization vulnerability that enables forceful browsing, potentially allowing unauthorized users to access restricted resources. Organizations using affected versions (0.0.0 to 1.12.0 and 2.0.0 to 2.1.3) should prioritize remediation to mitigate risks associated with unauthorized access and data exposure. Immediate attention is recommended for e-commerce platforms relying on these versions to ensure the integrity and security of user transactions.

CVE
CVE-2026-73475
Severity
CRITICAL
CVSS
9.1
EPSS
0.23%

Original NVD Description

Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing. This issue affects Commerce PayPal versions: from 0.0.0 to 1.12.0, from 2.0.0 to 2.1.3.

Related CVEs

Other vulnerabilities affecting the same vendor(s)