← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 6, 2026 · 17:17via CVEFeed

CVE-2026-82751 - Unbounded key authorization in mpp Tempo fee-payer sponsorship inflates gas cost and sponsors access-key provisioning

Brief

CVE ID : CVE-2026-82751

Published : Sept. 6, 2026, 5:17 p. m.

  • 3 hours, 31 minutes ago

Description : Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a large multiplier and to have the sponsor pay for provisioning an access key on the client's own account.

When the server sponsors Tempo payments, MPP. Methods. Tempo. FeePayerPolicy. measure/3 in lib/mpp/methods/tempo/fee_payer_policy. ex bounds the gas fields, the fee budget, the validity window and the access list of the client-signed 0x76 envelope, but does not check whether the envelope carries the optional key_authorization field.

A client can attach a fully signed key authorization, provisioning a new access key with token spending limits on its own account, alongside the normal payment call.

Read more on CVEFeed