CVE-2026-73475: Centarro Commerce PayPal
Critical severity, CVSS 9.1. EPSS: 0.4% chance of exploitation in the next 30 days.
Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing. This issue affects Commerce PayPal versions: from 0.0.0 to 1.12.0, from 2.0.0 to 2.1.3.
Affected products
- Centarro Commerce PayPal: before 1.12.0 (fixed in 1.12.0); from 2.0.0, before 2.1.3 (fixed in 2.1.3)
Published 2026-09-02. Last modified 2026-09-08.