Junglewise Threat Intelligence

CVE-2026-73475: Drupal Commerce PayPal access bypass in Payflow Link

CVE-2026-73475 · Severity: critical · CVSS 9.1 · Published 2026-09-02

Vendors: Drupal.

Executive brief

Drupal Commerce PayPal is a widely-used e-commerce payment integration module for Drupal that processes online transactions through PayPal. An insufficient validation flaw in the Payflow Link payment gateway allows attackers to artificially mark unpaid transactions as completed, enabling payment fraud and financial losses for merchants.

Technical details

This access bypass vulnerability exists in the Commerce PayPal module's transaction validation logic, specifically when using the Payflow Link payment gateway. The module fails to sufficiently validate payment transaction results in certain circumstances, permitting an attacker to forge a successful payment status without actually completing payment. The vulnerability is exploitable by any unauthenticated user interacting with the Payflow Link gateway—no special authentication or complex prerequisites are required. An attacker can leverage this to place orders and mark them as paid without payment, resulting in direct financial fraud. Patches are available in versions 2.1.3 and 8.x-1.12, released on 12 August 2026.

Affected products

  • Drupal Commerce PayPal 0.0.0 to 1.12.0, 2.0.0 to 2.1.3

Timeline

  • 2026-08-12: disclosed
  • 2026-08-12: patched: Commerce PayPal 2.1.3 and 8.x-1.12 released

References