CVE-2026-82751
Last modified
CVE-2026-82751 is a high-severity vulnerability rated 8.3/10 on the CVSS scale. Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a large multiplier and to have the sponsor pay for provisioning an access key on the client's own account. When the server sponsors Tempo payments, MPP.Methods.Tempo.FeePayerPolicy.measure/3 in lib/mpp/methods/tempo/fee_payer_policy.ex bounds the gas fields, the fee budget, the validity window and the access list of the client-signed 0x76 envelope, but does not check whether the envelope carries the optional key_authorization field. A client can attach a fully signed key authorization, provisioning a new access key with token spending limits on its own account, alongside the normal payment call. EPSS estimates a 0.33% chance of exploitation in the next 30 days.
Description
Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a large multiplier and to have the sponsor pay for provisioning an access key on the client's own account. When the server sponsors Tempo payments, MPP.Methods.Tempo.FeePayerPolicy.measure/3 in lib/mpp/methods/tempo/fee_payer_policy.ex bounds the gas fields, the fee budget, the validity window and the access list of the client-signed 0x76 envelope, but does not check whether the envelope carries the optional key_authorization field. A client can attach a fully signed key authorization, provisioning a new access key with token spending limits on its own account, alongside the normal payment call. The key and each limit entry are persistent storage writes billed as intrinsic gas to the sponsor, bounded only by the gas_limit ceiling. At the reporter's default of one key with three token limits the sponsored cost rises from about 46,587 gas to about 1,808,700 gas, and the client keeps a valid access key it paid nothing for. This issue affects mpp: from 0.2.0 before 0.16.1.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| ZenHive | mpp | >= 0.2.0, < 0.16.1 |
| ZenHive | mpp | >= d29d54e507918db00a5b65d90136b73166c017d7, < 0482572b47e1ffe1537ab80ab613d47b92833c2d |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-82751?
How severe is CVE-2026-82751?
How do I fix CVE-2026-82751?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-82746Missing Authorization vulnerability in ash-project ash allow…5.9
- CVE-2026-82747Incorrect Authorization vulnerability in ash-project ash ret…5.9
- CVE-2026-82748Incorrect Authorization vulnerability in ash-project ash aut…2.1
- CVE-2026-82749Incorrect Authorization vulnerability in ash-project ash wid…5.9
- CVE-2026-8275A vulnerability was detected in bettercap up to 2.41.5. Affe…3.7
- CVE-2026-82750Improper Validation of Specified Quantity in Input in ZenHiv…8.3
- CVE-2026-82752Improper Validation of Specified Quantity in Input vulnerabi…5.9
- CVE-2026-82753Allocation of Resources Without Limits or Throttling vulnera…8.2
- CVE-2026-82754Improper Protection of Alternate Path vulnerability in ash-p…6.3
- CVE-2026-82755Use of Cache Containing Sensitive Information vulnerability …6.3
- CVE-2026-82756Improper Encoding or Escaping of Output vulnerability in ash…6.3
- CVE-2026-82757Server-Side Request Forgery (SSRF) vulnerability in ash-proj…6.3
Are you affected by CVE-2026-82751?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
