Signature Spoofing Vulnerability in PrestaShop Virtual POS Module by Sipay Electronic Money and Payment Services Inc.
CVE-2026-86405

9.8CRITICAL

What is CVE-2026-86405?

The PrestaShop Virtual POS Module developed by Sipay Electronic Money and Payment Services Inc. has a vulnerability related to improper verification of cryptographic signatures. This flaw allows malicious actors to spoof valid signatures, which could lead to unauthorized transactions and potential data breaches. The affected versions range from 26.8.1 to versions prior to 26.9.1, highlighting a critical need for immediate updates to ensure transaction integrity and security.

Affected Version(s)

PrestaShop Virtual POS Module 26.8.1 < 26.9.1

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yasin SUER
.