CVE-2026-82751
8.3ZenHive · mpp
ZenHive mpp fails to validate the key_authorization field in sponsored payments, allowing unauthenticated attackers to inflate gas costs and provision unauthorized access keys at the sponsor's expense.
Executive summary
An unauthenticated remote attacker can exploit a validation flaw in ZenHive mpp to cause significant financial resource exhaustion and unauthorized access key provisioning.
Vulnerability
The vulnerability is an improper validation of input quantity (CWE-1284) within the MPP.Methods.Tempo.FeePayerPolicy.measure/3 function. An unauthenticated attacker can append a signed key authorization to a payment envelope, forcing the server to bill the sponsor for persistent storage writes that provision a new access key on the attacker's account.
Business impact
The exploitation of this vulnerability results in substantial financial loss due to the forced payment of inflated gas costs for unauthorized operations. With a CVSS score of 8.3, this high-severity flaw enables attackers to weaponize the sponsorship mechanism to generate free access keys, leading to potential long-term unauthorized access to the victim's ecosystem and direct monetary impact on the service provider.
Remediation
Immediate Action: Update ZenHive mpp to version 0.16.1 or later to implement the necessary validation checks for the key_authorization field.
Proactive Monitoring: Monitor system logs for abnormal spikes in sponsored gas usage or unexpected creations of access keys that do not align with expected user behavior.
Compensating Controls: Implement strict gas limit policies or rate limiting on sponsored payment endpoints to mitigate the impact of cost inflation attacks while the update is being deployed.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability presents a clear risk of resource abuse and unauthorized account provisioning. Organizations utilizing ZenHive mpp should prioritize upgrading to version 0.16.1 immediately to close the validation gap. Failure to patch may result in ongoing financial degradation and the proliferation of unauthorized access keys within the environment.
More ZenHive CVEs
Sources
Originally found and disclosed by Kian Kai Ang, Kian Kai Ang, with E.FU (remediation developer), Jonatan Männchen / EEF (coordinator), per the CVE Program record.