Split-Royalty Field Vulnerability in Klever Blockchain Implementation by Klever
CVE-2026-54755
9.6CRITICAL
What is CVE-2026-54755?
A vulnerability in the Klever-Go implementation of the Klever blockchain protocol allows for split-royalty fields to contain values exceeding a defined limit. This occurs prior to version 1.7.19, where manipulated values can lead to an inaccurate validation sum, enabling the creation of unbacked digital assets. The issue arises from the use of uint32 accumulators that fail to properly manage oversized entries, leading to unintended asset transfers and marketplace transactions. This flaw affects several components, including royalty payout paths and asset management, making it critical to adopt the latest version for security improvements.
Affected Version(s)
klever-go < 1.7.19
