CVE-2026-67581
Last modified
CVE-2026-67581 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Authentication Bypass by Capture-replay in ZenHive mpp allows an unauthenticated remote client to obtain paid resources by resubmitting one settled on-chain transfer. MPP.Methods.EVM.verify/2 accepts a transaction-hash credential and matches a transfer purely on token, to and amount (ERC-20) or to and value (native). It binds the proof neither to the challenge being verified nor to any record of prior use, and the generic MPP.Plug dedup store keys on challenge.id, which is regenerated for every 402 response. EPSS estimates a 0.50% chance of exploitation in the next 30 days.
Description
Authentication Bypass by Capture-replay in ZenHive mpp allows an unauthenticated remote client to obtain paid resources by resubmitting one settled on-chain transfer. MPP.Methods.EVM.verify/2 accepts a transaction-hash credential and matches a transfer purely on token, to and amount (ERC-20) or to and value (native). It binds the proof neither to the challenge being verified nor to any record of prior use, and the generic MPP.Plug dedup store keys on challenge.id, which is regenerated for every 402 response. On a static-price route, a single historical transfer matching the charge therefore satisfies an unbounded number of later charges, including transfers an attacker can read off a public block explorer. This issue affects mpp: from 0.3.0 before 0.6.3.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Zenhive | Machine Payments Protocol | >= 0.3.0, < 0.6.4 |
References
- https://cna.erlef.org/cves/CVE-2026-67581.htmlThird Party Advisory
- https://osv.dev/vulnerability/EEF-CVE-2026-67581Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-67581?
How severe is CVE-2026-67581?
How do I fix CVE-2026-67581?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-67567A flaw was found in the multicloud-operators-subscription co…9.9
- CVE-2026-67568The distributed Mira Android APK v4.5.15.4 allows an attacke…9.1
- CVE-2026-6757Invalid pointer in the JavaScript: WebAssembly component. Th…6.3
- CVE-2026-67578FA-50 all versions miss authentication for some configuratio…7.5
- CVE-2026-67579Deserialization of Untrusted Data vulnerability in ash-proje…7.4
- CVE-2026-6758Use-after-free in the JavaScript: WebAssembly component. Thi…7.5
- CVE-2026-67585Allocation of Resources Without Limits or Throttling vulnera…8.7
- CVE-2026-67587Apache Airflow's Task SDK rebuilt a `Callback` object from s…8.8
- CVE-2026-67588A pre-authentication attacker could leverage unbounded symbo…7.5
- CVE-2026-67589A pre-authentication attacker could leverage type size/count…7.5
- CVE-2026-6759Use-after-free in the Widget: Cocoa component. This vulnerab…7.5
- CVE-2026-67590A pre-authentication attacker could leverage type nesting to…7.5
Are you affected by CVE-2026-67581?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
