PT-2026-7957 · Cedipay · Cedipay
Published
2026-02-12
·
Updated
2026-02-23
·
CVE-2026-26063
CVSS v4.0
8.8
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
CediPay versions prior to 1.2.3
Description
A flaw exists in CediPay that allows attackers to bypass input validation within the transaction API. Exploitation could lead to unauthorized transactions, exposure of sensitive financial data, and compromise of payment integrity. The issue affects all deployments running versions prior to the patched release and poses a high risk of potential financial loss and reputational damage. The vulnerability resides in the lack of proper input validation when processing transactions via the API.
Recommendations
Upgrade to CediPay version 1.2.3 or later.
If upgrading is not immediately possible, restrict API access to trusted networks or IP ranges.
Enforce strict input validation at the application layer.
Monitor transaction logs for anomalies or suspicious activity.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cedipay