Authentication Bypass Vulnerability in ZenHive mpp Affects EVM Transactions
CVE-2026-67581
What is CVE-2026-67581?
The ZenHive mpp contains a vulnerability that allows an unauthenticated remote client to exploit its transaction verification mechanism. Specifically, an attacker can achieve unauthorized access to paid resources by repeatedly resubmitting a previously settled on-chain transfer. The method used for verification fails to bind transaction proof to previous usage records, allowing a single historical transfer matching specific criteria (such as token and amount) to be utilized across multiple requests. This flaw stems from how the MPP.Methods.EVM.verify/2 function checks transaction-hash credentials, which can lead to potential abuse of the system by leveraging publicly accessible data from block explorers.
Affected Version(s)
mpp 0.3.0 < 0.6.3
mpp 65b9e425ce27631c786a5b380b5e4c5ae607ec6d
