Improper Verification of Cryptographic Signature in OpenCart Virtual POS Module by Sipay Electronic Money and Payment Services Inc.
CVE-2026-85531
9.8CRITICAL
Key Information:
- Vendor
- CVE Published:
- 9 October 2026
What is CVE-2026-85531?
The OpenCart Virtual POS Module developed by Sipay Electronic Money and Payment Services Inc. is susceptible to an improper verification of cryptographic signatures. This vulnerability allows for potential signature spoofing due to inadequate validation mechanisms. Specifically, versions from 26.8.2 before 26.9.1 are impacted, creating significant security risks for users relying on this payment processing module.
Affected Version(s)
OpenCart Virtual POS Module 26.8.2 < 26.9.1
