Project machine name: 
monobank
Date: 
2026-September-02
Vulnerability: 
Access bypass
Affected versions: 
<1.0.3
CVE IDs: 
CVE-2026-84918
Description: 

The Monobank payment API module provides integration with Monobank acquiring payments.

The module did not verify the Monobank webhook signature before processing payment status callbacks.

Solution: 

Install the latest version:

  • If you use the Monobank payment API module, upgrade to the monobank 1.0.3.
Coordinated By: