THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-82751 — Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a large multiplier and to have the sponsor pay for provisioning an access key on the client's own account. When

[NVD] CVE-2026-82751 — Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a large multiplier and to have the sponsor pay for provisioning an access key on the client's own account. When

mednvdPublished 2026-09-06

CVE-2026-82751 CVSS: None Published: 2026-09-06T17:17:56.070

Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a large multiplier and to have the sponsor pay for provisioning an access key on the client's own account.

When the server sponsors Tempo payments, MPP.Methods.Tempo.Fee

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-82751