CVE-2026-86840
Deferred Deferred - Pending Action

Improper Authorization in Bifrost vtoken-minting and slpx Pallets

Vulnerability report for CVE-2026-86840, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-10

Assigner: CERT/CC

Description

The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission attribution. A signed account can supply an arbitrary registered `channel_id` when minting tokens without verifying that the caller is authorized to mint on behalf of that channel. This allows an attacker to inflate a channel's recorded mint volume and cause protocol commission payments to be disproportionately distributed to that channel during commission settlement.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-10
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The vulnerability is in Bifrost's vtoken-minting and slpx pallets. It allows a signed account to provide any registered channel_id when minting tokens without checking if they are authorized to mint for that channel. This lets an attacker artificially increase a channel's mint volume and manipulate commission payments to receive more than their share.

Impact Analysis

If you are a channel operator or user of Bifrost, this vulnerability could lead to unfair distribution of protocol commissions. Attackers may inflate their channel's mint volume, causing commission payments to be incorrectly allocated, reducing rewards for legitimate channels.

Mitigation Strategies

Implement strict authorization checks to ensure only authorized accounts can mint tokens for specific channels. Review and validate channel commission attribution logic to prevent arbitrary channel_id submissions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86840. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart