Project:
Project machine name:
monobankDate:
2026-September-02
Vulnerability:
Access bypass
Affected versions:
<1.0.3
CVE IDs:
CVE-2026-84918
Description:
The Monobank payment API module provides integration with Monobank acquiring payments.
The module did not verify the Monobank webhook signature before processing payment status callbacks.
Solution:
Install the latest version:
- If you use the Monobank payment API module, upgrade to the monobank 1.0.3.
Reported By:
Coordinated By:
- Swan Kalata (akalata) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team