Vulnerability Details CVE-2026-73475
Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing. This issue affects Commerce PayPal versions: from 0.0.0 to 1.12.0, from 2.0.0 to 2.1.3.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 14.0%
CVSS Severity
CVSS v3 Score 9.1
Products affected by CVE-2026-73475
-
cpe:2.3:a:centarro:commerce_paypal:*