Smart Contract Vulnerability in MultiversX Multisig Implementation
CVE-2026-106511

Currently unrated

Key Information:

Vendor
CVE Published:
6 October 2026

What is CVE-2026-106511?

The MultiversX multisig implementation presents a significant risk due to a lack of proper authorization checks. Specifically, the Proposer role is improperly enabled to execute actions that should require multiple signatures, permitting unauthorized fund transfers. In this instance, an account assigned to the Proposer role can drain the entire EGLD or ESDT balances from a contract in just two transactions, posing a serious threat to the security of assets managed through this multisig system.

Affected Version(s)

multisig-improved GitHub commit 2e6dbea40f9b8ac165572a9efd4304804762a299

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.