Improper Authorization Vulnerability in Bifrost's vtoken-minting and slpx Pallets
CVE-2026-86840

Currently unrated

Key Information:

Status
Vendor
CVE Published:
8 September 2026

What is CVE-2026-86840?

The vtoken-minting and slpx pallets in Bifrost have a vulnerability that allows a signed account to supply any registered channel_id when minting tokens. This lack of authorization verification permits an attacker to inflate the recorded mint volume for a channel, leading to skewed protocol commission payments during settlement. Essentially, this flaw compromises the intended attribution mechanism, which can unfairly advantage certain channels in the distribution of commissions.

Affected Version(s)

Bifrost 0 <= 2022.02

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.