Split-Royalty Field Vulnerability in Klever Blockchain Implementation by Klever
CVE-2026-54755

9.6CRITICAL

Key Information:

Vendor

Klever-io

Status
Vendor
CVE Published:
28 August 2026

What is CVE-2026-54755?

A vulnerability in the Klever-Go implementation of the Klever blockchain protocol allows for split-royalty fields to contain values exceeding a defined limit. This occurs prior to version 1.7.19, where manipulated values can lead to an inaccurate validation sum, enabling the creation of unbacked digital assets. The issue arises from the use of uint32 accumulators that fail to properly manage oversized entries, leading to unintended asset transfers and marketplace transactions. This flaw affects several components, including royalty payout paths and asset management, making it critical to adopt the latest version for security improvements.

Affected Version(s)

klever-go < 1.7.19

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.