Executive brief
Drupal Commerce Realex / Global Payments is a module used by e-commerce websites to process credit card transactions. A security flaw in how the module handles payment confirmations could allow an attacker to bypass payment verification steps. This could potentially lead to orders being marked as paid without a valid transaction occurring, impacting revenue and order fulfillment integrity.
Technical details
The Drupal Commerce Realex / Global Payments module fails to sufficiently verify the authenticity of payment responses returned by the Global Payments Hosted Payment Page (HPP) when configured with the redirect payment method. Specifically, the module does not validate the cryptographic signature of the response against the merchant's shared secret. This allows an attacker to perform 'forceful browsing' by manually navigating to the payment return URL with crafted parameters to simulate a successful transaction. The lightbox payment method is unaffected as it correctly validates signatures. The issue is resolved in version 3.0.2 by implementing cryptographic verification of the redirect response.
Affected products
- Drupal Commerce Realex / Global Payments < 3.0.2
Timeline
- 2026-06-24: patched: Version 3.0.2 released
- 2026-06-24: advisory: Drupal security advisory SA-CONTRIB-2026-058 published
- 2026-07-10: disclosed: CVE-2026-13238 published to NVD