Improper Input Validation in ZenHive mpp Affects Gas Cost Management
CVE-2026-82750

8.3HIGH

Key Information:

Vendor

Zenhive

Status
Vendor
CVE Published:
6 September 2026

What is CVE-2026-82750?

The improper input validation in ZenHive's mpp allows unauthenticated remote clients to exploit fee-payer gas costs during sponsored payments. Through a vulnerability in the MPP.Methods.Tempo.FeePayerPolicy, clients can inflate the gas expenses significantly when delegating account control. The gas limit is breached by the inclusion of unauthorized delegations, leading to a dramatic increase in gas costs from approximately 46,575 to 1,884,087. This enables clients to make sponsors pay for actions they did not authorize, directly impacting the sponsor's financial liabilities during transaction processes.

Affected Version(s)

mpp 0.2.0 < 0.16.1

mpp d29d54e507918db00a5b65d90136b73166c017d7 < 0482572b47e1ffe1537ab80ab613d47b92833c2d

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kian Kai Ang
Kian Kai Ang
E.FU
Jonatan Männchen / EEF
.