Authentication Bypass in ZenHive mpp Affects Token Transactions
CVE-2026-73136

8.2HIGH

Key Information:

Vendor

Zenhive

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-73136?

The vulnerability in ZenHive mpp allows an unauthenticated third party to exploit the authentication process through capture-replay attacks. By replaying previously settled TIP-20 transfer transactions, attackers can obtain paid resources intended for others. This flaw arises from a failure to properly bind a specific challenge to the static memo used within method_config. As a result, attackers can leverage public transfers and request new challenges while presenting transaction hashes from legitimate transfers. This exposes systems to misuse and unauthorized access, highlighting the need for immediate patching and security best practices.

Affected Version(s)

mpp 0.6.1 < 0.6.4

mpp 542a525563c2fcedd670b593437deca81c6797a4 < 2207d7f456ae14c1d3fcacc6f635bf4f8cee1a34

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

E.FU
E.FU
Jonatan Männchen / EEF
.