CVE-2026-86840
N/A
N/A
Summary
The vtoken-minting and slpx pallets in Bifrost contain an improper authorization vulnerability in channel commission attribution. A signed account can supply an arbitrary registered channel_id when minting tokens without verifying that the caller is authorized to mint on behalf of that channel. This allows an attacker to inflate a channel's recorded mint volume and cause protocol commission payments to be disproportionately distributed to that channel during commission settlement.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Bitfrost.io | Bifrost | 0 <= 2022.02 | affected |
Weaknesses
- CWE-862 Missing Authorization
- CWE-639 Authorization Bypass Through User-Controlled Key
References
- https://docs.bifrost.io/faq/what-are-vtokens
- https://gist.github.com/prasanna8585/ffd112b1a125ca4c5533fdce45ef57c1
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.