CVE-2026-0750 Details
Description
Improper Verification of Cryptographic Signature vulnerability in Drupal Drupal Commerce Paybox Commerce Paybox on Drupal 7.X allows Authentication Bypass.This issue affects Drupal Commerce Paybox: from 7-x-1.0 through 7.X-1.5.
An authentication bypass vulnerability has been identified in the Drupal Commerce Paybox module for Drupal 7, specifically in versions 7.x-1.0 through 7.x-1.5. This vulnerability allows attackers to mark payments as completed and finalize orders without entering a credit card number. The issue arises from improper verification of cryptographic signatures, enabling signature forgery that can be exploited to bypass payment authentication.
Users can upgrade to Drupal Commerce Paybox version 7.x-1.6, which includes the necessary patch. For those using Drupal 7, the latest version can be downloaded from the Tag1 Consulting release page. Additionally, HeroDevs offers a patched version of this module for their customers.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://d7es.tag1.com/security-advisories/commerce-paybox-moderately-critical-payment-bypass-vulnerability | [email protected] | Third Party Advisory |
| https://www.herodevs.com/vulnerability-directory/cve-2026-0750 | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-347 | Improper Verification of Cryptographic Signature | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| verifone commerce paybox | >= 7-x-1.0, <= 7.x-1.5 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 9, 2026 | Initial Analysis | [email protected] |
| Jan 28, 2026 | New CVE Received | [email protected] |