PT-2026-97538 · Klever-Go · Klever-Go

CVE-2026-82405

·

Published

2026-09-23

·

Updated

2026-10-01

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Klever-Go versions prior to 1.7.20
Description An issue exists in the KleverUpdateAccountPermission built-in function where the authorization check incorrectly uses the vmInput.RecipientAddr variable instead of the authenticated vmInput.CallerAddr. This allows an attacker-controlled smart contract to specify a victim account as the RecipientAddr, which the system then validates against the victim's own default self-signer permissions. Consequently, the UpdatePermission() function can be used to replace the victim's entire permission set with attacker-supplied Owner permissions. This can lead to full account takeover, enabling the theft of assets or permanent lockout of the account without requiring the victim's private key or signature. This issue specifically affects accounts with configured permissions; accounts without stored permissions and the native transaction path are not affected.
Recommendations Update Klever-Go to version 1.7.20. As a temporary mitigation, restrict the use of the KleverUpdateAccountPermission function via smart contracts until the update is applied.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82405
GHSA-97CV-X867-6XHM
GO-2026-6582

Affected Products

Klever-Go