Vulnerability Details CVE-2026-13238
Incorrect Authorization vulnerability in Drupal Commerce Realex / Global Payments allows Forceful Browsing. This issue affects Commerce Realex / Global Payments versions: from 0.0.0 to 3.0.2.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 3.7%
CVSS Severity
CVSS v3 Score 4.8
Products affected by CVE-2026-13238
-
cpe:2.3:a:stella:commerce_realex_/_global_payments:2.0.0
-
cpe:2.3:a:stella:commerce_realex_/_global_payments:2.0.1
-
cpe:2.3:a:stella:commerce_realex_/_global_payments:2.0.2
-
cpe:2.3:a:stella:commerce_realex_/_global_payments:3.0.0
-
cpe:2.3:a:stella:commerce_realex_/_global_payments:3.0.1