CVE-2026-85531 is a critical (CVSS 9.8) improper cryptographic signature verification flaw in Sipay's OpenCart Virtual POS Module that allows signature spoofing.
What Is It
CVE-2026-85531 affects the OpenCart Virtual POS Module from Sipay Electronic Money and Payment Services Inc. The CVE record describes it as an improper verification of cryptographic signature vulnerability that "allows Signature Spoofing by Improper Validation." It is classified as CWE-347 (Improper Verification of Cryptographic Signature).
The CVE was assigned by USOM ([email protected]) and published to NVD on 2026-10-09. NVD lists its analysis status as "Deferred," so NVD has not added its own enrichment, such as CPE mappings.
Why It Matters
The CNA gave the flaw a CVSS v3.1 base score of 9.8 (Critical) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. That vector means:
- Network-exploitable with low attack complexity
- No privileges and no user interaction required
- High impact to confidentiality, integrity, and availability
The module handles payments in OpenCart stores, so a signature check that can be spoofed is a serious integrity risk. The record doesn't describe specific attack scenarios.
Exploitation status: The CISA KEV data supplied for this brief contains no entry for this CVE, so known exploitation in the wild has not been confirmed.
What's Vulnerable
- Vendor: Sipay Electronic Money and Payment Services Inc.
- Product: OpenCart Virtual POS Module
- Affected versions: 26.8.2 up to, but not including, 26.9.1 (semver)
- Default status: Versions outside this range are listed as unaffected
The NVD record has no CPEs listed.
Patch Status
The affected range ends before version 26.9.1, which makes 26.9.1 the first release outside the vulnerable range. If you run version 26.8.2 through 26.9.0, upgrade to 26.9.1 or later and check the vendor and USOM advisory for confirmation. No CISA KEV required action or due date applies, because the supplied KEV data has no entry for this CVE.