PT-2026-96708 · Zenhive · Zenhive Mpp

·

CVE-2026-87119

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v4.0

8.2

High

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ZenHive mpp versions 0.14.0 through 0.16.1
Description An authentication bypass via capture-replay allows an attacker with a captured subscription activation credential to repeatedly charge a payer. The issue occurs because the payer signs a Tempo KeyAuthorization over the chain id, key type, key id, expiry, limits, and scopes, but does not tie the signature to the specific challenge that prompted it. The function MPP.Methods.Tempo.KeyAuthorization.verify/3 in lib/mpp/methods/tempo/key authorization.ex pins signed fields against the subscription request using a static per-endpoint server key, meaning one signed authorization can verify against any challenge for the same terms. Furthermore, MPP.Methods.Tempo.Subscription.activate/4 deduplicates activations by challenge id; therefore, using a captured credential with a new challenge creates a different deduplication key, allowing claim activation to succeed and the subscription transaction to be broadcast again. This results in repeated first-period settlement charges to the payer's wallet. This issue specifically affects deployments offering Tempo subscriptions that utilize subscription access key private key in the Tempo method config.
Recommendations Update ZenHive mpp to version 0.16.2 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-87119
GHSA-P9FV-9W58-95X2

Affected Products

Zenhive Mpp