CVE-2026-89420
— UNSCOREDpublic exploit availablePublished 2026-09-22 · Updated 2026-09-22
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
Improper Validation of Specified Quantity in Input in ZenHive mpp allows a client holding an open payment channel to obtain paid resources without being charged. MPP.Session.Actions.accept_voucher/3 in lib/mpp/session/actions.ex treats a voucher whose cumulativeAmount equals the channel's already-accepted cumulative amount as an idempotent success, returning the channel unchanged without calling maybe_spend/2. The credential verifies, the protected resource is served, and spent and units stay where they were. Because the server issues a fresh challenge per request and the credential replay store keys on challenge id and payload, the same signed voucher can be re-presented under every new challenge, so one paid voucher yields an unbounded number of paid units. The path is reachable from any method built on MPP.Session.Method through the Plug, MCP, JSON-RPC and WebSocket transports. This issue affects mpp: from 0.14.0 before 0.16.2.
Weaknesses
CWE-1284
Public exploit & PoC references
All references
- https://cna.erlef.org/cves/CVE-2026-89420.html
- https://github.com/ZenHive/mpp/commit/7270edc1dcfb58250cc5ee812876609206564165
- https://github.com/ZenHive/mpp/commit/82df569c898be1137189e3648e1edb4af6363651
- https://github.com/ZenHive/mpp/security/advisories/GHSA-8c63-r789-xrrf
- https://osv.dev/vulnerability/EEF-CVE-2026-89420
- https://github.com/ZenHive/mpp/security/advisories/GHSA-8c63-r789-xrrf
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2025-36178
- UNSCOREDCVE-2026-12974
- HIGHCVE-2026-70378PoC
- MEDIUMCVE-2026-73436
- MEDIUMCVE-2026-76899PoC
- MEDIUMCVE-2026-93015PoC
- HIGHCVE-2026-93345
- HIGHCVE-2026-93749PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.