Description
Improper verification of cryptographic signature vulnerability in Sipay Electronic Money and Payment Services Inc. PrestaShop Virtual POS Module allows Signature Spoofing by Improper Validation.

This issue affects PrestaShop Virtual POS Module: from 26.8.1 before 26.9.1.
Published: 2026-10-09
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Signature Spoofing – payment validation bypass
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an improper verification of a cryptographic signature in the PrestaShop Virtual POS Module, allowing attackers to forge payment signatures and bypass strict validation checks. This flaw, identified as CWE-347, can enable malicious transactions to be processed without detection, compromising the integrity and authenticity of electronic payments.

Affected Systems

PrestaShop Virtual POS Module by Sipay Electronic Money and Payment Services Inc. is vulnerable in all releases from 26.8.1 up to but not including 26.9.1. Any site running these versions is at risk unless changes are applied.

Risk and Exploitability

With a CVSS score of 9.8, this issue represents high severity. The EPSS score is not available, so precise exploitation probability is unknown, but the lack of a KEV listing does not diminish the potential impact. The likely attack vector is remote, whereby an adversary sends forged signed requests to the module’s API or web interface, potentially from the public Internet. Once exploited, the attacker can submit fraudulent payment data and compromise financial integrity.

Generated by OpenCVE AI on October 9, 2026 at 14:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the PrestaShop Virtual POS Module to version 26.9.1 or later, which implements proper signature verification.
  • Verify that the module configuration enforces signature checks and that no custom bypass logic is enabled.
  • Continuously monitor transaction logs and network traffic for attempts to submit forged signatures, and apply additional access controls or monitoring tools as a supplementary safeguard.

Generated by OpenCVE AI on October 9, 2026 at 14:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 13:15:00 +0000

Type Values Removed Values Added
Description Improper verification of cryptographic signature vulnerability in Sipay Electronic Money and Payment Services Inc. PrestaShop Virtual POS Module allows Signature Spoofing by Improper Validation. This issue affects PrestaShop Virtual POS Module: from 26.8.1 before 26.9.1.
Title Payment Validation Bypass in Sipay Electronic Money's SanalPos PrestaShop
Weaknesses CWE-347
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-10-09T12:52:43.902Z

Reserved: 2026-09-07T11:25:25.549Z

Link: CVE-2026-86405

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-09T13:17:11.100

Modified: 2026-10-09T13:21:13.267

Link: CVE-2026-86405

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T15:00:08Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature