
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-26063 is an improper input validation vulnerability in CediPay, an npm payment processing package (cedipay-core), that allows attackers to bypass input validation in the transaction API. All deployments running versions prior to 1.2.3 are affected. The vulnerability was published on February 12, 2026, via a GitHub Security Advisory, and subsequently added to the NVD on February 19, 2026. It carries a CVSS v4 base score of 8.8 (High) (GitHub Advisory).
The vulnerability is rooted in improper input validation (CWE-20) within CediPay's transaction processing mechanism. Attackers can send crafted network requests to the transaction API without authentication or user interaction, bypassing the application's input validation controls and manipulating transaction data. No special privileges or attack prerequisites are required, making the attack surface broad for any internet-exposed deployment (GitHub Advisory). No public proof-of-concept code has been identified at this time (Feedly).
Successful exploitation could result in unauthorized financial transactions, exposure of sensitive financial data, and compromise of payment integrity within affected CediPay deployments. The high confidentiality impact and low integrity impact scores indicate that attackers can read sensitive transaction data and make limited unauthorized modifications. Organizations face potential financial loss and reputational damage as a result (GitHub Advisory).
There is currently no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.085–0.127%, placing it in the lower percentiles for near-term exploitation likelihood. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
The vulnerability has been fixed in cedipay-core version 1.2.3; all users should upgrade immediately, as all versions prior to 1.2.3 remain vulnerable (GitHub Advisory). If an immediate upgrade is not feasible, the following interim mitigations are recommended: (1) restrict API access to trusted networks or IP ranges, (2) enforce strict input validation at the application layer, and (3) monitor transaction logs for anomalies or suspicious activity. These workarounds reduce exposure but do not fully remediate the vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."