Executive brief
Drupal Commerce CyberSource is a payment gateway integration module for Drupal's e-commerce platform. A timing-based vulnerability in the Secure Acceptance Hosted Checkout gateway allows attackers to bypass payment integrity checks and trick the site into falsely recording completed payments, potentially leading to fraudulent transactions and revenue loss.
Technical details
The module fails to correctly verify the integrity of data returned by the CyberSource payment provider in the Secure Acceptance Hosted Checkout (SAHC) gateway integration. An attacker can exploit timing discrepancies in the verification logic to perform a timing attack, allowing them to forge or modify payment responses without proper validation. This vulnerability requires network access to intercept or manipulate payment data, and affects only the SAHC integration path. A fix is available in version 1.10.0 and later.
Affected products
- Drupal Commerce CyberSource 0.0.0 to 1.9.x
Timeline
- 2026-08-26: disclosed: Security advisory SA-CONTRIB-2026-106 published
- 2026-09-02: patched: Version 1.10.0 and 2.0.0 released with fix; version 2.1.0 released 2026-09-16