Junglewise Threat Intelligence

CVE-2026-81159: Drupal Commerce CyberSource timing attack in payment verification

CVE-2026-81159 · Severity: low · CVSS 3.7 · Published 2026-09-02

Vendors: Drupal, Packagist:Https://Packages.Drupal.Org/8.

Executive brief

Drupal Commerce CyberSource is a payment gateway integration module for Drupal's e-commerce platform. A timing-based vulnerability in the Secure Acceptance Hosted Checkout gateway allows attackers to bypass payment integrity checks and trick the site into falsely recording completed payments, potentially leading to fraudulent transactions and revenue loss.

Technical details

The module fails to correctly verify the integrity of data returned by the CyberSource payment provider in the Secure Acceptance Hosted Checkout (SAHC) gateway integration. An attacker can exploit timing discrepancies in the verification logic to perform a timing attack, allowing them to forge or modify payment responses without proper validation. This vulnerability requires network access to intercept or manipulate payment data, and affects only the SAHC integration path. A fix is available in version 1.10.0 and later.

Affected products

  • Drupal Commerce CyberSource 0.0.0 to 1.9.x

Timeline

  • 2026-08-26: disclosed: Security advisory SA-CONTRIB-2026-106 published
  • 2026-09-02: patched: Version 1.10.0 and 2.0.0 released with fix; version 2.1.0 released 2026-09-16

References