Authentication Bypass Vulnerability in ZenHive mpp Software
CVE-2026-87119

8.2HIGH

Key Information:

Vendor

Zenhive

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-87119?

The vulnerability in ZenHive mpp allows an attacker to exploit a flaw in the authentication mechanism. By capturing a subscription activation credential, an attacker can repeatedly initiate charges to the payer's wallet without additional user interaction. The flaw arises due to the usage of static keys for verification of signed fields against subscription requests. This static key not only validates old credentials but also permits new challenges under the same subscription terms. As a result, each replay attempt can issue new charges and reauthorize the server key within the constraints of the subscription’s expiry and associated chain logic, severely jeopardizing user funds and subscription integrity.

Affected Version(s)

mpp 0.14.0 < 0.16.2

mpp db464dfa9a86ccda58f0827101f6da6bd8aafa78 < 4b6eaec02af0e8485cfb4ff68f467d075ed5dd6f

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

E.FU
E.FU
Jonatan Männchen / EEF
.