OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-89420

HIGH · CVSS 7.1 EPSS 0.41% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-22 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

ZenHive mpp versions from 0.14.0 to before 0.16.2 are vulnerable due to improper validation of input, allowing clients with open payment channels to exploit a flaw in voucher processing. This vulnerability enables an attacker to repeatedly use a single paid voucher to obtain an unlimited number of resources without incurring charges, posing a significant financial risk. Organizations utilizing affected versions should prioritize immediate updates to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-89420
Severity
HIGH
CVSS
7.1
EPSS
0.41%

Original NVD Description

Improper Validation of Specified Quantity in Input in ZenHive mpp allows a client holding an open payment channel to obtain paid resources without being charged. MPP.Session.Actions.accept_voucher/3 in lib/mpp/session/actions.ex treats a voucher whose cumulativeAmount equals the channel's already-accepted cumulative amount as an idempotent success, returning the channel unchanged without calling maybe_spend/2. The credential verifies, the protected resource is served, and spent and units stay where they were. Because the server issues a fresh challenge per request and the credential replay store keys on challenge id and payload, the same signed voucher can be re-presented under every new challenge, so one paid voucher yields an unbounded number of paid units. The path is reachable from any method built on MPP.Session.Method through the Plug, MCP, JSON-RPC and WebSocket transports. This issue affects mpp: from 0.14.0 before 0.16.2.