CVE-2026-0750
Authentication Bypass via Signature Verification Flaw in Drupal Commerce Paybox
Publication date: 2026-01-28
Last updated on: 2026-03-09
Assigner: Drupal.org
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| verifone | commerce_paybox | From 7-x-1.0 (inc) to 7.x-1.5 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-347 | The product does not verify, or incorrectly verifies, the cryptographic signature for data. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an Improper Verification of Cryptographic Signature in the Drupal Commerce Paybox module for Drupal 7.X. It allows an attacker to bypass authentication by exploiting the failure to properly verify cryptographic signatures in versions from 7-x-1.0 through 7.X-1.5.
How can this vulnerability impact me? :
This vulnerability can allow an attacker to bypass authentication controls, potentially gaining unauthorized access to the system or sensitive functions within the Drupal Commerce Paybox module. This could lead to unauthorized transactions or manipulation of commerce-related data.