Date: 
2026-August-26
Vulnerability: 
Insufficient input validation
Affected versions: 
<1.10.0
CVE IDs: 
CVE-2026-81159
Description: 

This module integrates Drupal Commerce with the CyberSource payment gateway.

The module does not correctly verify the integrity of data returned by the payment provider. A timing attack could allow an attacker to trick the site into registering that payment has been received even if it hasn't.

This issue only affects the Secure Acceptance Hosted Checkout gateway integration.

Solution: 

Install the latest version:

Reported By: 
Coordinated By: