CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-13238

Critical · CVSS 9.1

drupal/commerce_realex — Incorrect Authorization / Forceful Browsing (CWE-863)

CVSS
9.1
nvd
EPSS
0.18%
8th pct
KEV
No
Class
oss containerizable
CWE-863

Description

Incorrect Authorization vulnerability in Drupal Commerce Realex / Global Payments allows Forceful Browsing. This issue affects Commerce Realex / Global Payments versions: from 0.0.0 to 3.0.2.

Search profile — drives PoC discovery

Symbols commerce_realexCommerce RealexGlobal Paymentsdrupal/commerce_realexsa-contrib-2026-058
Keywords CVE-2026-13238commerce_realexdrupal commerce realex exploitdrupal global payments forceful browsingdrupal incorrect authorization PoCCWE-863 drupalsa-contrib-2026-058commerce_realex authorization bypass
Versions: 0.0.0 to 3.0.2

Affected packages

Packagist:https://packages.drupal.org/8 drupal/commerce_realex 0 → 3.0.2

References

Status: enriched · ingested 2026-07-13T18:00:21.000Z · profiled 2026-07-13T18:30:21.000Z