PT-2026-97539 · Klever-Go+1 · Klever-Go+1

CVE-2026-82409

·

Published

2026-09-23

·

Updated

2026-09-24

CVSS v4.0

8.4

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Klever-Go versions prior to 1.7.20
Description An issue exists in the Elasticsearch indexer component where the serializedDataForUpdateAccounts function in indexer/common.go fails to escape the acc.Name variable when constructing bulk JSON and NDJSON requests. The SetAccountName transaction allows account names containing quotes, backslashes, and newlines, which are stored in the consensus account state. When an indexer processes these accounts, an attacker can inject arbitrary keys or new bulk operations into the request. This allows for the creation, overwriting, or deletion of documents across any index the indexer has permissions to write to, such as transactions, blocks, accounts, proposals, assets, and marketplaces. Additionally, specially crafted names can cause Elasticsearch to reject entire bulk batches, leading to a denial-of-indexing where the explorer or API serves stale data. Because the payload is stored in the replicated state, it affects all current and future indexers and persists through historical re-indexing.
Recommendations Update to version 1.7.20. As a temporary mitigation, restrict the allowed characters for account names in the SetAccountName function to reject control characters, quotes, and backslashes.

Exploit

Fix

Improper Encoding or Escaping of Output

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82409
GHSA-7C7C-373R-GFJJ

Affected Products

Elasticsearch
Klever-Go