🔐 CVE Alert

CVE-2026-87119

UNKNOWN 0.0

mpp Tempo subscription key authorization is not bound to the issuing challenge, allowing a captured activation credential to be replayed

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Authentication Bypass by Capture-replay in ZenHive mpp allows an attacker holding a captured subscription activation credential to charge the payer repeatedly. The payer signs a Tempo KeyAuthorization over the chain id, key type, key id, expiry, limits and scopes only, with nothing tying it to the challenge that prompted it. MPP.Methods.Tempo.KeyAuthorization.verify/3 in lib/mpp/methods/tempo/key_authorization.ex pins each of those signed fields against the subscription request, and the access key it pins is a static per-endpoint server key, so one signed authorization verifies against every challenge the server issues for the same subscription terms. MPP.Methods.Tempo.Subscription.activate/4 deduplicates activations by challenge id, so presenting the captured credential under a fresh challenge produces a different dedup key, claim_activation succeeds, and the subscription transaction is built and broadcast again. Each replay charges the payer's wallet a new first-period settlement and re-authorizes the server key, bounded only by the subscription expiry and the chain's own semantics for re-installing an existing key. This issue affects mpp: from 0.14.0 before 0.16.2.

CWE CWE-294
Vendor zenhive
Product mpp
Published Sep 22, 2026
Last Updated Sep 22, 2026
Stay Ahead of the Next One

Get instant alerts for zenhive mpp

Be the first to know when new unknown vulnerabilities affecting zenhive mpp are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

ZenHive / mpp
0.14.0 < 0.16.2
ZenHive / mpp
db464dfa9a86ccda58f0827101f6da6bd8aafa78 < 4b6eaec02af0e8485cfb4ff68f467d075ed5dd6f

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/ZenHive/mpp/security/advisories/GHSA-p9fv-9w58-95x2 cna.erlef.org: https://cna.erlef.org/cves/CVE-2026-87119.html osv.dev: https://osv.dev/vulnerability/EEF-CVE-2026-87119 github.com: https://github.com/ZenHive/mpp/commit/db464dfa9a86ccda58f0827101f6da6bd8aafa78 github.com: https://github.com/ZenHive/mpp/commit/4b6eaec02af0e8485cfb4ff68f467d075ed5dd6f

Credits

E.FU E.FU Jonatan Männchen / EEF