---
id: CVE-2026-85531
title: >-
  Improper verification of cryptographic signature vulnerability in Sipay
  Electronic Money and Payment Services Inc
summary: >-
  Improper verification of cryptographic signature vulnerability in Sipay
  Electronic Money and Payment Services Inc. OpenCart Virtual POS Module allows
  Signature Spoofing by Improper Validation.


  This issue affects OpenCart Virtual POS Mod…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-347
published: '2026-10-09'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T13:21:13.267'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85531'
references:
  - url: 'https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1286'
    label: iletisim@usom.gov.tr
tags:
  - nvd
ingestedAt: '2026-10-09T13:58:52.545Z'
---

## Overview

Improper verification of cryptographic signature vulnerability in Sipay Electronic Money and Payment Services Inc. OpenCart Virtual POS Module allows Signature Spoofing by Improper Validation.

This issue affects OpenCart Virtual POS Module: from 26.8.2 before 26.9.1.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
