๐Ÿ” CVE Alert

CVE-2026-86840

CRITICAL 9.1

Bifrost Unauthorized Channel Commission Attribution Allows Commission Diversion

CVSS Score
9.1
EPSS Score
0.0%
EPSS Percentile
0th

The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission attribution. A signed account can supply an arbitrary registered `channel_id` when minting tokens without verifying that the caller is authorized to mint on behalf of that channel. This allows an attacker to inflate a channel's recorded mint volume and cause protocol commission payments to be disproportionately distributed to that channel during commission settlement.

Vendor bitfrost.io
Product bifrost
Published Sep 8, 2026
Last Updated Sep 10, 2026
Stay Ahead of the Next One

Get instant alerts for bitfrost.io bifrost

Be the first to know when new critical vulnerabilities affecting bitfrost.io bifrost are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Bitfrost.io / Bifrost
0 โ‰ค 2022.02

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
docs.bifrost.io: https://docs.bifrost.io/faq/what-are-vtokens gist.github.com: https://gist.github.com/prasanna8585/ffd112b1a125ca4c5533fdce45ef57c1