CVE-2026-86405 is a critical (CVSS 9.8) flaw in how Sipay's PrestaShop Virtual POS Module checks cryptographic signatures. Based on its CVSS vector, an attacker could spoof signatures over the network without logging in.
What Is It
CVE-2026-86405 is an improper verification of cryptographic signature vulnerability (CWE-347) in the PrestaShop Virtual POS Module from Sipay Electronic Money and Payment Services Inc. The NVD description says the flaw "allows Signature Spoofing by Improper Validation." The description is brief, but it suggests the module does not properly validate signatures, which could let an attacker present forged signatures that the module accepts as genuine.
The CVE was published on 2026-10-09 by USOM ([email protected]), Turkey's national cyber incident response center. Its NVD status is currently "Deferred."
Why It Matters
USOM rates the flaw CVSS v3.1 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H:
- Attack vector: Network
- Attack complexity: Low
- Privileges required: None
- User interaction: None
- Impact: High confidentiality, integrity, and availability impact
According to this CVSS assessment, an unauthenticated remote attacker could exploit the flaw with little effort and without any victim action. The affected component is a payment (virtual POS) module, which makes the integrity of signature checks especially important.
Exploitation status: CVE-2026-86405 is not in the CISA Known Exploited Vulnerabilities (KEV) catalog, and the supplied sources do not confirm active exploitation.
What's Vulnerable
- Vendor: Sipay Electronic Money and Payment Services Inc.
- Product: PrestaShop Virtual POS Module
- Affected versions: 26.8.1 up to, but not including, 26.9.1
- Default status: Versions outside this range are listed as unaffected
The NVD record lists no CPE entries.
Patch Status
According to the vendor-supplied version data, the issue affects versions before 26.9.1, so version 26.9.1 falls outside the affected range. Administrators running PrestaShop with Sipay's Virtual POS Module at version 26.8.1 or later, but below 26.9.1, should upgrade to 26.9.1 or later. They should also check the USOM advisory (TR-26-1287) for any additional vendor guidance.
Because the CVE is not in KEV, CISA has issued no KEV-mandated required action or due date.