Improper access control in Monobank payment API - CVE-2026-84918
Published: September 3, 2026
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the affected module does not verify the Monobank webhook signature before processing payment status callbacks. A remote attacker can bypass payment verification and manipulate payment status callbacks.