Improper Verification of Cryptographic Signature vulnerability in Drupal Drupal Commerce Paybox Commerce Paybox on Drupal 7.X allows Authentication Bypass.This issue affects Drupal Commerce Paybox: from 7-x-1.0 through 7.X-1.5.
History

Mon, 09 Mar 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Verifone
Verifone commerce Paybox
CPEs cpe:2.3:a:verifone:commerce_paybox:*:*:*:*:*:drupal:*:*
Vendors & Products Verifone
Verifone commerce Paybox
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Thu, 29 Jan 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Drupal
Drupal drupal Commerce Paybox
Vendors & Products Drupal
Drupal drupal Commerce Paybox

Wed, 28 Jan 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 28 Jan 2026 19:15:00 +0000

Type Values Removed Values Added
Description Improper Verification of Cryptographic Signature vulnerability in Drupal Drupal Commerce Paybox Commerce Paybox on Drupal 7.X allows Authentication Bypass.This issue affects Drupal Commerce Paybox: from 7-x-1.0 through 7.X-1.5.
Title Payment bypass in Commerce Paybox
Weaknesses CWE-347
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published: 2026-01-28T18:53:42.343Z

Updated: 2026-01-28T19:25:29.820Z

Reserved: 2026-01-08T19:51:40.852Z

Link: CVE-2026-0750

cve-icon Vulnrichment

Updated: 2026-01-28T19:25:20.505Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-28T19:16:24.620

Modified: 2026-03-09T14:38:54.277

Link: CVE-2026-0750

cve-icon Redhat

No data.