CVE-2026-85531 PUBLISHED

Payment Validation Bypass in Sipay Electronic Money's OpenCart 3.x

Assigner: TR-CERT
Reserved: 04.09.2026 Published: 09.10.2026 Updated: 09.10.2026

Improper verification of cryptographic signature vulnerability in Sipay Electronic Money and Payment Services Inc. OpenCart Virtual POS Module allows Signature Spoofing by Improper Validation.

This issue affects OpenCart Virtual POS Module: from 26.8.2 before 26.9.1.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor Sipay Electronic Money and Payment Services Inc.
Product OpenCart Virtual POS Module
Versions Default: unaffected
  • affected from 26.8.2 to 26.9.1 (excl.)

Credits

  • Yasin SUER finder

References

Problem Types

  • CWE-347 Improper verification of cryptographic signature CWE

Impacts

  • CAPEC-475 Signature Spoofing by Improper Validation