CyberRota Analysis
AI-GeneratedA vulnerability in Drupal Commerce Realex/Global Payments allows for forceful browsing due to incorrect authorization, potentially exposing sensitive data or functionalities to unauthorized users. This affects all versions from 0.0.0 to 3.0.2, and organizations utilizing these versions should prioritize patching to mitigate the risk of unauthorized access.
CVE
CVE-2026-13238
Severity
MEDIUM
CVSS
4.8
EPSS
0.14%
Original NVD Description
Incorrect Authorization vulnerability in Drupal Commerce Realex / Global Payments allows Forceful Browsing. This issue affects Commerce Realex / Global Payments versions: from 0.0.0 to 3.0.2.