CVE-2026-85531
Deferred
Deferred - Pending Action
Signature Spoofing in OpenCart Virtual POS Module
Vulnerability report for CVE-2026-85531, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-09
Last updated on: 2026-10-09
Assigner: Computer Emergency Response Team of the Republic of Turkey
Description
Description
Improper verification of cryptographic signature vulnerability in Sipay Electronic Money and Payment Services Inc. OpenCart Virtual POS Module allows Signature Spoofing by Improper Validation.
This issue affects OpenCart Virtual POS Module: from 26.8.2 before 26.9.1.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Sipay | Electronic | Money and Payment Services Inc. OpenCart Virtual POS Module 26.8.2 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-347 | The product does not verify, or incorrectly verifies, the cryptographic signature for data. |