Drupal · Commerce Paypal · CVE-2026-73475
**Name of the Vulnerable Software and Affected Versions**
Commerce PayPal versions 0.0.0 through 1.12.0
Commerce PayPal versions 2.0.0 through 2.1.3
**Description**
An incorrect authorization issue allows forceful browsing. The module fails to sufficiently validate transaction results when using the Payflow Link payment gateway, which enables a malicious user to mark transactions as completed without providing payment.
**Recommendations**
Update Commerce PayPal versions 0.0.0 through 1.12.0 to a version newer than 1.12.0.
Update Commerce PayPal versions 2.0.0 through 2.1.3 to a version newer than 2.1.3.