3.7
CVE-2026-81159
- EPSS 0.26%
- Veröffentlicht 02.09.2026 12:32:12
- Zuletzt bearbeitet 16.09.2026 20:19:00
- Erkennungen
Commerce CyberSource - Moderately critical - Insufficient input validation - SA-CONTRIB-2026-106
Observable Timing Discrepancy vulnerability in Drupal Commerce CyberSource allows Brute Force. This issue affects Commerce CyberSource versions: from 0.0.0 to 1.10.0.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Centarro ≫ Commerce Cybersource SwPlatform drupal Version >= 8.x-1.0 < 8.x-1.10
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.26% | 0.17 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 3.7 | 2.2 | 1.4 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
|
CWE-208 Observable Timing Discrepancy
Two separate operations in a product require different amounts of time to complete, in a way that is observable to an actor and reveals security-relevant information about the state of the product, such as whether a particular operation was successful or not.
https://www.drupal.org/sa-contrib-2026-106