OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-82406

HIGH · CVSS 7.1 EPSS 0.34% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The Klever-Go implementation of the Klever blockchain protocol prior to version 1.7.20 contains a vulnerability in its marketplace function that allows sellers to settle auctions without proper bid validation, potentially leading to financial loss for later bidders. This flaw can result in a situation where a later bidder is charged for an NFT that has already been delivered, while being unable to recover their funds. Organizations using affected versions of Klever-Go should prioritize upgrading to version 1.7.20 to mitigate this high-severity risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82406
Severity
HIGH
CVSS
7.1
EPSS
0.34%

Original NVD Description

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the native marketplace function core/kapp/market/market.go Buy does not check IsClaimed before accepting a bid. A seller can use the Claim seller-accept branch to settle a resting-bid auction while leaving the claimed order loadable with a future EndTime and stale CurrentBid and CurrentBidder values. A later bidder can submit a higher bid, be debited, and cause the previous bidder to receive a refund even though the NFT has already been delivered. Because Claim and CancelOrder reject the later bidder when IsClaimed is true, the later bidder cannot obtain the NFT or recover the funds. This issue is fixed in version 1.7.20.