Skip to content
firewallpulse
Bits, bytes and breaking security news
Vulnerabilities

Sipay OpenCart CVE-2026-85531: Critical Signature Bypass Flaw Fixed in Version 26.9.1

A critical flaw in the Sipay OpenCart module allows attackers to bypass cryptographic signature checks and spoof transaction data.

Sipay OpenCart CVE-2026-85531: Critical Signature Bypass Flaw Fixed in Version 26.9.1
Illustration: Firewall Pulse

Key points

  • CVE-2026-85531 carries a CVSS score of 9.8, rated critical.
  • The vulnerability stems from improper verification of cryptographic signatures.
  • Sipay has released version 26.9.1 to address the issue.

Sipay Electronic Money and Payment Services Inc. has addressed a severe security flaw in its OpenCart Virtual POS Module. The vulnerability, tracked as CVE-2026-85531, permits signature spoofing due to inadequate validation of cryptographic signatures. This weakness allows an attacker to manipulate payment data without detection, potentially leading to fraudulent transactions.

Root cause

The core issue is classified under CWE-347, Improper Verification of Cryptographic Signature. The module fails to correctly validate the digital signatures attached to payment requests. This lack of rigorous checking means that an attacker can craft malicious payloads that appear legitimate to the system. The software accepts these spoofed signatures as valid, bypassing the intended security controls designed to ensure data integrity and authenticity.

Attack path

An attacker exploits this flaw by submitting a payment request with a forged or invalid cryptographic signature. Because the module does not properly verify the signature against the expected key or algorithm, it processes the request as if it were authentic. This allows the attacker to alter transaction details, such as amounts or recipient accounts, without triggering security alerts. The attack relies entirely on the module’s failure to reject improperly signed data.

Affected versions

The vulnerability affects specific versions of the OpenCart Virtual POS Module. According to the National Vulnerability Database, the issue is present in versions starting from 26.8.2 up to, but not including, 26.9.1. Any deployment using a version within this range is susceptible to signature spoofing attacks.

Mitigation

  • Update the OpenCart Virtual POS Module to version 26.9.1 or later.
  • Verify that all payment transactions are validated using strict cryptographic checks.
  • Monitor logs for any anomalies in signature validation results.
  • Review integration settings to ensure no legacy versions are in use.

What to do and how to stay safe: Sipay

  • Audit your OpenCart installations to identify the current version of the Sipay Virtual POS Module.
  • Apply the vendor-provided update to version 26.9.1 as soon as possible.
  • Implement additional logging for payment signature validation events to detect potential abuse.
  • Review access controls for payment processing endpoints to limit exposure.

General security guidance from the Firewall Pulse newsroom. It is not confirmed advice from the organisations named in this story.

Frequently asked questions

What is the CVSS score for CVE-2026-85531?

The CVSS score is 9.8, which is rated as critical severity.

Which versions of the Sipay OpenCart module are affected?

Versions from 26.8.2 before 26.9.1 are affected by this vulnerability.

Is there a fix available for this signature spoofing issue?

Yes, Sipay has released version 26.9.1 which resolves the improper signature verification flaw.

Sources

  1. CVE Program
  2. NVD
SipayOpenCartCVE-2026-85531Virtual POSCryptographic Signature

Related stories