Project: 
Date: 
2026-August-12
Vulnerability: 
Access bypass
Affected versions: 
< 1.12.0 || >= 2.0.0 < 2.1.3
CVE IDs: 
CVE-2026-73475
Description: 

This module enables you to pay for Commerce transactions using Paypal.

The module doesn't sufficiently validate the transaction result in certain circumstances, allowing a malicious user to mark transactions placed without payment.

This vulnerability only affects sites using the Payflow Link payment gateway.

Solution: 
Coordinated By: