Improper Authorization Vulnerability in Bifrost's vtoken-minting and slpx Pallets
CVE-2026-86840
Currently unrated
What is CVE-2026-86840?
The vtoken-minting and slpx pallets in Bifrost have a vulnerability that allows a signed account to supply any registered channel_id when minting tokens. This lack of authorization verification permits an attacker to inflate the recorded mint volume for a channel, leading to skewed protocol commission payments during settlement. Essentially, this flaw compromises the intended attribution mechanism, which can unfairly advantage certain channels in the distribution of commissions.
Affected Version(s)
Bifrost 0 <= 2022.02
