CVE-2026-106511

Summary

MultiversX's multisig-improved (repository: mx-multisig-and-modules) reference implementation of their on-chain multisig smart contract system contains a vulnerability where a missing independent authorization check allows any account with the Proposer role to perform explicitly barred actions. This vulnerability allows the Proposer role to move funds alone, draining 100% of a contract's EGLD/ESDT balance in two transactions with zero signatures.

Affected Software

VendorProductVersion RangeStatus
MultiversX Labs S.R.L.multisig-improvedGitHub commit 2e6dbea40f9b8ac165572a9efd4304804762a299affected

Weaknesses

  • CWE-862 Missing Authorization
  • CWE-863 Incorrect Authorization
  • CWE-306 Missing Authentication for Critical Function

References