CVE-2026-26063 HIGH

CVE-2026-26063: CediPay Affected by Improper Input Validation in Payment Processing

Vendor Xpertforextradeinc
Product CediPay
Weakness CWE-20 · Input validation
Published February 19, 2026
Last update February 19, 2026

CVSS base score

8.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

CediPay is a crypto-to-fiat app for the Ghanaian market. A vulnerability in CediPay prior to version 1.2.3 allows attackers to bypass input validation in the transaction API. The issue has been fixed in version 1.2.3. If upgrading is not immediately possible, restrict API access to trusted networks or IP ranges; enforce strict input validation at the application layer; and/or monitor transaction logs for anomalies or suspicious activity. These mitigations reduce exposure but do not fully eliminate the vulnerability.

Key dates

02Disclosure timeline

February 19, 2026 CVE published
February 19, 2026 Record updated