PT-2026-97539 · Klever-Go+1 · Klever-Go+1
CVE-2026-82409
·
Published
2026-09-23
·
Updated
2026-09-24
CVSS v4.0
8.4
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Klever-Go versions prior to 1.7.20
Description
An issue exists in the Elasticsearch indexer component where the
serializedDataForUpdateAccounts function in indexer/common.go fails to escape the acc.Name variable when constructing bulk JSON and NDJSON requests. The SetAccountName transaction allows account names containing quotes, backslashes, and newlines, which are stored in the consensus account state. When an indexer processes these accounts, an attacker can inject arbitrary keys or new bulk operations into the request. This allows for the creation, overwriting, or deletion of documents across any index the indexer has permissions to write to, such as transactions, blocks, accounts, proposals, assets, and marketplaces. Additionally, specially crafted names can cause Elasticsearch to reject entire bulk batches, leading to a denial-of-indexing where the explorer or API serves stale data. Because the payload is stored in the replicated state, it affects all current and future indexers and persists through historical re-indexing.Recommendations
Update to version 1.7.20.
As a temporary mitigation, restrict the allowed characters for account names in the
SetAccountName function to reject control characters, quotes, and backslashes.Exploit
Fix
Improper Encoding or Escaping of Output
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Elasticsearch
Klever-Go