Authentication Bypass Vulnerability in ZenHive mpp Affects EVM Transactions
CVE-2026-67581

8.7HIGH

Key Information:

Vendor

Zenhive

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-67581?

The ZenHive mpp contains a vulnerability that allows an unauthenticated remote client to exploit its transaction verification mechanism. Specifically, an attacker can achieve unauthorized access to paid resources by repeatedly resubmitting a previously settled on-chain transfer. The method used for verification fails to bind transaction proof to previous usage records, allowing a single historical transfer matching specific criteria (such as token and amount) to be utilized across multiple requests. This flaw stems from how the MPP.Methods.EVM.verify/2 function checks transaction-hash credentials, which can lead to potential abuse of the system by leveraging publicly accessible data from block explorers.

Affected Version(s)

mpp 0.3.0 < 0.6.3

mpp 65b9e425ce27631c786a5b380b5e4c5ae607ec6d

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

E.FU
E.FU
Jonatan Männchen / EEF
.