Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 08 Sep 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 |
Tue, 08 Sep 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission attribution. A signed account can supply an arbitrary registered `channel_id` when minting tokens without verifying that the caller is authorized to mint on behalf of that channel. This allows an attacker to inflate a channel's recorded mint volume and cause protocol commission payments to be disproportionately distributed to that channel during commission settlement. | |
| Title | Bifrost Unauthorized Channel Commission Attribution Allows Commission Diversion | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2026-09-08T15:29:48.572Z
Reserved: 2026-09-08T14:43:37.022Z
Link: CVE-2026-86840
No data.
Status : Received
Published: 2026-09-08T16:18:37.597
Modified: 2026-09-08T16:18:37.597
Link: CVE-2026-86840
No data.
OpenCVE Enrichment
Updated: 2026-09-08T17:00:02Z
-
CWE-284
Improper Access Control