CVE-2026-13238
Critical · CVSS 9.1drupal/commerce_realex — Incorrect Authorization / Forceful Browsing (CWE-863)
- CVSS
- 9.1
- nvd
- EPSS
- 0.18%
- 8th pct
- KEV
- No
- Class
- oss containerizable
- CWE-863
Description
Incorrect Authorization vulnerability in Drupal Commerce Realex / Global Payments allows Forceful Browsing. This issue affects Commerce Realex / Global Payments versions: from 0.0.0 to 3.0.2.
Search profile — drives PoC discovery
Symbols commerce_realexCommerce RealexGlobal Paymentsdrupal/commerce_realexsa-contrib-2026-058
Keywords CVE-2026-13238commerce_realexdrupal commerce realex exploitdrupal global payments forceful browsingdrupal incorrect authorization PoCCWE-863 drupalsa-contrib-2026-058commerce_realex authorization bypass
Versions: 0.0.0 to 3.0.2
Affected packages
| Packagist:https://packages.drupal.org/8 | drupal/commerce_realex | 0 → 3.0.2 |
References
Status: enriched · ingested 2026-07-13T18:00:21.000Z · profiled 2026-07-13T18:30:21.000Z