CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-94299: elegro Crypto Payment 0 through 1.0.1

CVE-2026-94299. CVSS 3.1 base score 6.5 (MEDIUM, Source advisory).

Affected technology

elegro Crypto Payment · 0 through 1.0.1
Vendor not specified by the source

Description’s affected range: through 1.0.1 does not require a shared secret to be configured before trusting incoming payment notification requests

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

Unauthenticated attackers can forge payment confirmations and change the status of arbitrary orders on any installation where that secret has been left at its default empty value. Source advisory’s CVSS 3.1 assessment (base score 6.5/10) rates confidentiality and integrity impact as low; availability impact as none.

Published

CWE
CWE-863
CCR priority
26.0 /100 (P4)
CVSS 3.1
6.5 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N · Source advisory
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-94299.html