PT-2026-97538 · Klever-Go · Klever-Go
CVE-2026-82405
·
Published
2026-09-23
·
Updated
2026-10-01
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Klever-Go versions prior to 1.7.20
Description
An issue exists in the
KleverUpdateAccountPermission built-in function where the authorization check incorrectly uses the vmInput.RecipientAddr variable instead of the authenticated vmInput.CallerAddr. This allows an attacker-controlled smart contract to specify a victim account as the RecipientAddr, which the system then validates against the victim's own default self-signer permissions. Consequently, the UpdatePermission() function can be used to replace the victim's entire permission set with attacker-supplied Owner permissions. This can lead to full account takeover, enabling the theft of assets or permanent lockout of the account without requiring the victim's private key or signature. This issue specifically affects accounts with configured permissions; accounts without stored permissions and the native transaction path are not affected.Recommendations
Update Klever-Go to version 1.7.20.
As a temporary mitigation, restrict the use of the
KleverUpdateAccountPermission function via smart contracts until the update is applied.Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Klever-Go