CediPay is a crypto-to-fiat app for the Ghanaian market. A vulnerability in CediPay prior to version 1.2.3 allows attackers to bypass input validation in the transaction API. The issue has been fixed in version 1.2.3. If upgrading is not immediately possible, restrict API access to trusted networks or IP ranges; enforce strict input validation at the application layer; and/or monitor transaction logs for anomalies or suspicious activity. These mitigations reduce exposure but do not fully eliminate the vulnerability.
History

Thu, 19 Feb 2026 19:30:00 +0000

Type Values Removed Values Added
Description CediPay is a crypto-to-fiat app for the Ghanaian market. A vulnerability in CediPay prior to version 1.2.3 allows attackers to bypass input validation in the transaction API. The issue has been fixed in version 1.2.3. If upgrading is not immediately possible, restrict API access to trusted networks or IP ranges; enforce strict input validation at the application layer; and/or monitor transaction logs for anomalies or suspicious activity. These mitigations reduce exposure but do not fully eliminate the vulnerability.
Title CediPay Affected by Improper Input Validation in Payment Processing
Weaknesses CWE-20
References
Metrics cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-02-19T18:53:47.314Z

Reserved: 2026-02-10T18:01:31.900Z

Link: CVE-2026-26063

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-02-19T20:25:41.910

Modified: 2026-02-19T20:25:41.910

Link: CVE-2026-26063

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.