CVE-2026-86405: CWE-347 Improper verification of cryptographic signature in Sipay Electronic Money and Payment Services Inc. PrestaShop Virtual POS Module
Description
CVE-2026-86405 is a critical vulnerability in the Sipay Electronic Money and Payment Services Inc. PrestaShop Virtual POS Module. It involves improper verification of cryptographic signatures, which allows signature spoofing due to improper validation. This affects versions from 26.8.1 up to but not including 26.9.1. The vulnerability has a high CVSS score of 9.8, indicating severe impact on confidentiality, integrity, and availability.
CVSS v3.1
Score 9.8critical
Affected software
Sipay Electronic Money and Payment Services Inc.
PrestaShop Virtual POS Module
pkg:composer/prestashop/virtual-pos-moduleRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2026-86405) in the PrestaShop Virtual POS Module by Sipay Electronic Money and Payment Services Inc. is caused by improper verification of cryptographic signatures (CWE-347). This flaw allows attackers to spoof signatures by bypassing validation checks, potentially leading to unauthorized actions or data manipulation within the payment module. The affected versions are >=26.8.1 and <26.9.1. The CVSS v3.1 base score is 9.8, reflecting network attack vector, low complexity, no privileges required, no user interaction, and high impact on confidentiality, integrity, and availability.
Potential Impact
Successful exploitation of this vulnerability could allow an attacker to spoof cryptographic signatures, potentially leading to unauthorized transactions, data tampering, or disruption of payment services. The impact is critical as it affects core security controls of the payment module, compromising confidentiality, integrity, and availability of the system.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. There are no patch links provided in the available data. Users should monitor official vendor communications for updates and apply any official fixes once available. Until then, consider restricting access to the affected module and monitoring for suspicious activity related to signature validation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- TR-CERT
- Date Reserved
- 2026-09-07T11:25:25.549Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ac8e6472cdf04f65657df32
Added to database: 10/09/2026, 13:04:07 UTC
Last enriched: 10/09/2026, 13:18:31 UTC
Last updated: 10/09/2026, 18:57:32 UTC
Views: 18
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.