CVE-2026-13223
Deferred Deferred - Pending Action
Payment Status Validation Flaw in Computop Integration

Publication date: 2026-06-25

Last updated on: 2026-06-25

Assigner: rami.io

Description
Our payment integration with Computop-based payment methods did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it to the system for a different payment, gaining access to multiple valid tickets with only one payment.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-25
Last Modified
2026-06-25
Generated
2026-06-25
AI Q&A
2026-06-25
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Currently, no data is known.
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-841 The product supports a session in which more than one behavior must be performed by an actor, but it does not properly ensure that the actor performs the behaviors in the required sequence.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Impact Analysis

The impact of this vulnerability is that an attacker could obtain multiple valid tickets or services by making only one payment.

This could lead to financial loss for the service provider and unauthorized access to paid services or events by the attacker.

Executive Summary

This vulnerability occurs in the payment integration with Computop-based payment methods where the system does not properly validate payment status responses.

An attacker can exploit this by taking a successful payment status response from one payment and using it for a different payment, thereby gaining access to multiple valid tickets with only one actual payment.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-13223. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart