Improper Input Validation in ZenHive mpp Affects Remote Clients
CVE-2026-88255

6.3MEDIUM

Key Information:

Vendor

Zenhive

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-88255?

An issue in ZenHive's mpp allows an unauthenticated remote client to exploit improper validation of input, leading to the possibility of passing the Tempo duplicate-submission gate twice using a single signed transaction. This occurs due to the handling of transaction forms and reserve keys, which enables duplicate transactions to be accepted when the same transaction is submitted with different recovery id encodings. As a result, an attacker can create multiple valid Payment-Receipts from what should be a single on-chain payment, posing significant risks to transaction integrity.

Affected Version(s)

mpp 0.2.0 < 0.16.2

mpp f8904666061fbab695874856d8fcd02c471dfe1b

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

E.FU
E.FU
Jonatan Männchen / EEF
.