THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-82750 — Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a large multiplier and to have the sponsor pay for EIP-7702 account delegations of the client's choosing. When t

[NVD] CVE-2026-82750 — Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a large multiplier and to have the sponsor pay for EIP-7702 account delegations of the client's choosing. When t

mednvdPublished 2026-09-06

CVE-2026-82750 CVSS: None Published: 2026-09-06T17:17:55.867

Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a large multiplier and to have the sponsor pay for EIP-7702 account delegations of the client's choosing.

When the server sponsors Tempo payments, MPP.Methods.Tempo.FeeP

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-82750