CVE-2026-106511
N/A
N/A
Summary
MultiversX's multisig-improved (repository: mx-multisig-and-modules) reference implementation of their on-chain multisig smart contract system contains a vulnerability where a missing independent authorization check allows any account with the Proposer role to perform explicitly barred actions. This vulnerability allows the Proposer role to move funds alone, draining 100% of a contract's EGLD/ESDT balance in two transactions with zero signatures.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MultiversX Labs S.R.L. | multisig-improved | GitHub commit 2e6dbea40f9b8ac165572a9efd4304804762a299 | affected |
Weaknesses
- CWE-862 Missing Authorization
- CWE-863 Incorrect Authorization
- CWE-306 Missing Authentication for Critical Function
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.