Improper Input Validation in ZenHive mpp Allows Unauthenticated Exploitation
CVE-2026-82751

8.3HIGH

Key Information:

Vendor

Zenhive

Status
Vendor
CVE Published:
6 September 2026

What is CVE-2026-82751?

The ZenHive mpp product is vulnerable due to improper validation of specified input quantities, enabling unauthenticated remote clients to significantly inflate the gas costs billed to sponsors of payments. This occurs within the MPP.Methods.Tempo.FeePayerPolicy.measure/3 function, where bound gas fields and limits do not check the optional key_authorization field. This oversight allows clients to exploit the payment method by attaching a signed key authorization request, leading to large increases in sponsorship costs, as clients can provision access keys on their accounts without financial accountability. As the sponsored transactions scale, the gas usage can escalate drastically, raising legitimate concerns about cost management and resource allocation for the sponsors.

Affected Version(s)

mpp 0.2.0 < 0.16.1

mpp d29d54e507918db00a5b65d90136b73166c017d7 < 0482572b47e1ffe1537ab80ab613d47b92833c2d

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kian Kai Ang
Kian Kai Ang
E.FU
Jonatan Männchen / EEF
.