Vulnerability in Klever-Go Affects Marketplace Settlement Mechanism
CVE-2026-54754

9.6CRITICAL

Key Information:

Vendor

Klever-io

Status
Vendor
CVE Published:
28 August 2026

What is CVE-2026-54754?

The Klever-Go implementation of the Klever blockchain protocol has a vulnerability in its marketplace settlement mechanism. Prior to version 1.7.19, the system's handling of referral and royalty percentages can be manipulated by asset owners, leading to potential discrepancies in payments. An asset owner could create a valid listing and subsequently use the AssetTrigger UpdateRoyalties function to adjust the referral and royalty percentages in such a way that they exceed the buyer's bid. Consequently, transactions through MarketBuy, BuyItNow, or auction Claim settlements may end up crediting more KLV or sale currency than initially paid by the buyer, resulting in the creation of unbacked currency and threatening the integrity of the token supply. The issue has been resolved in version 1.7.19.

Affected Version(s)

klever-go < 1.7.19

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.