PT-2026-96708 · Zenhive · Zenhive Mpp
CVSS v4.0
8.2
High
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ZenHive mpp versions 0.14.0 through 0.16.1
Description
An authentication bypass via capture-replay allows an attacker with a captured subscription activation credential to repeatedly charge a payer. The issue occurs because the payer signs a Tempo
KeyAuthorization over the chain id, key type, key id, expiry, limits, and scopes, but does not tie the signature to the specific challenge that prompted it. The function MPP.Methods.Tempo.KeyAuthorization.verify/3 in lib/mpp/methods/tempo/key authorization.ex pins signed fields against the subscription request using a static per-endpoint server key, meaning one signed authorization can verify against any challenge for the same terms. Furthermore, MPP.Methods.Tempo.Subscription.activate/4 deduplicates activations by challenge id; therefore, using a captured credential with a new challenge creates a different deduplication key, allowing claim activation to succeed and the subscription transaction to be broadcast again. This results in repeated first-period settlement charges to the payer's wallet. This issue specifically affects deployments offering Tempo subscriptions that utilize subscription access key private key in the Tempo method config.Recommendations
Update ZenHive mpp to version 0.16.2 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zenhive Mpp