Skip to content
Threat Feed
critical advisory

CVE-2026-85531 Signature Spoofing in Sipay OpenCart Module

An improper cryptographic signature verification flaw in the Sipay OpenCart Virtual POS Module allows remote attackers to spoof signatures and manipulate transaction processing.

CVE search metadata

CVE search record: CVE-2026-85531. Severity: critical. CVSS: 9.8. KEV: no. Product: OpenCart Virtual POS Module (26.8.2 - 26.9.0). Brief: CVE-2026-85531 Signature Spoofing in Sipay OpenCart Module. Brief link: https://feed.craftedsignal.io/briefs/2026-10-sipay-opencart-signature-spoofing/

The Sipay Electronic Money and Payment Services Inc. OpenCart Virtual POS Module contains a critical vulnerability, identified as CVE-2026-85531, stemming from improper verification of cryptographic signatures. This vulnerability impacts module versions 26.8.2 through 26.9.0. By failing to correctly validate the integrity and authenticity of payment callback signatures, the module allows an unauthenticated remote attacker to craft malicious requests that appear legitimate to the payment gateway. Successful exploitation permits signature spoofing, potentially enabling attackers to manipulate transaction status or finalize unauthorized payments. This flaw represents a significant risk to the integrity of financial transactions managed via the OpenCart platform using the Sipay integration.

Impact

Successful exploitation of this vulnerability allows unauthorized transaction manipulation within the affected OpenCart storefronts. An attacker can bypass the intended cryptographic security controls to force the system to accept fraudulent payment confirmations. This impact primarily affects the financial integrity and accounting reconciliations for businesses utilizing the vulnerable Sipay module.

Recommendation

  1. Immediately upgrade the Sipay OpenCart Virtual POS Module to version 26.9.1 or later to remediate the signature validation logic.
  2. Audit transaction logs for the affected module to identify any payment confirmation requests that deviate from standard cryptographic signing patterns associated with the Sipay gateway.
  3. Contact the Sipay technical support team to verify that no suspicious transactions were processed during the window of vulnerability.

Immediate actions

Upgrade OpenCart Virtual POS Module to version 26.9.1 or later

IT Operations 24h

Mitigations

Upgrade to version 26.9.1

immediate IT Operations

CVE-2026-85531