THREAT OPS › Threat News › [NVD] CVE-2026-82751 — Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a large multiplier and to have the sponsor pay for provisioning an access key on the client's own account.
When
[NVD] CVE-2026-82751 — Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a large multiplier and to have the sponsor pay for provisioning an access key on the client's own account. When
CVE-2026-82751 CVSS: None Published: 2026-09-06T17:17:56.070
Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a large multiplier and to have the sponsor pay for provisioning an access key on the client's own account.
When the server sponsors Tempo payments, MPP.Methods.Tempo.Fee
Indicators of compromise
- CVE-2026-82751cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-82751