PT-2026-7957 · Cedipay · Cedipay

Published

2026-02-12

·

Updated

2026-02-23

·

CVE-2026-26063

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions CediPay versions prior to 1.2.3
Description A flaw exists in CediPay that allows attackers to bypass input validation within the transaction API. Exploitation could lead to unauthorized transactions, exposure of sensitive financial data, and compromise of payment integrity. The issue affects all deployments running versions prior to the patched release and poses a high risk of potential financial loss and reputational damage. The vulnerability resides in the lack of proper input validation when processing transactions via the API.
Recommendations Upgrade to CediPay version 1.2.3 or later. If upgrading is not immediately possible, restrict API access to trusted networks or IP ranges. Enforce strict input validation at the application layer. Monitor transaction logs for anomalies or suspicious activity.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2026-26063
GHSA-WVR6-395C-5PXR

Affected Products

Cedipay