PT-2026-78535 · Zenhive · Zenhive Mpp

·

CVE-2026-67581

·

Published

2026-08-19

·

Updated

2026-08-19

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ZenHive mpp versions 0.3.0 through 0.6.2
Description An authentication bypass exists that allows an unauthenticated remote client to obtain paid resources by resubmitting a settled on-chain transfer. The MPP.Methods.EVM.verify/2 function accepts a transaction-hash credential and matches a transfer based solely on the token, recipient, and amount for ERC-20 tokens, or the recipient and value for native tokens. Because the proof is not bound to the challenge being verified or to a record of prior use, and the MPP.Plug deduplication store keys are based on challenge.id (which is regenerated for every 402 response), a single historical transfer matching the charge can satisfy multiple subsequent charges. This allows an attacker to use transfers found on a public block explorer to bypass payment requirements on static-price routes.
Recommendations Update ZenHive mpp to version 0.6.3 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67581
GHSA-VP5H-XH25-44WF

Affected Products

Zenhive Mpp