PatchSiren cyber security CVE debrief
CVE-2026-42278 UltraDAGcom CVE debrief
UltraDAG StateEngine contains a critical authorization bypass in SmartTransferTx processing. When transactions originate from a Pocket (a derived sub-address), the engine fails to resolve the pocket's parent account before checking spending policies. Because pockets lack their own SmartAccountConfig entries, the check_spending_policy method defaults to an authorized/no-policy result. This allows immediate bypass of parent account protections including vault delays and daily spending limits, enabling complete drainage of all pockets on an account. The vulnerability affects all versions prior to commit fb6ef59.
- Vendor
- UltraDAGcom
- Product
- core
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-08
- Original CVE updated
- 2026-05-19
- Advisory published
- 2026-05-08
- Advisory updated
- 2026-05-19
Who should care
UltraDAG node operators, blockchain developers implementing sub-address or pocket architectures, security auditors of DAG-BFT consensus systems, and organizations holding UDAG assets in Pocket-structured accounts
Technical summary
The vulnerability exists in UltraDAG's StateEngine implementation of SmartTransferTx. Pockets are virtual sub-addresses mapped to parent accounts via pocket_to_parent but lack independent SmartAccountConfig entries. The check_spending_policy method receives the Pocket address as the account identifier, fails to find a configuration, and defaults to authorized. This occurs before any parent account lookup, allowing complete circumvention of configured delays and limits. The fix in commit fb6ef59 ensures proper parent resolution prior to policy evaluation.
Defensive priority
Critical
Recommended defensive actions
- Upgrade UltraDAG core to commit fb6ef59 or later immediately
- Audit all SmartTransferTx transactions originating from Pocket addresses since deployment for unauthorized spending
- Review and strengthen policy enforcement pipeline to ensure parent account resolution occurs before any policy check
- Implement additional validation to reject transactions from virtual addresses lacking explicit policy configurations
- Monitor for anomalous Pocket-to-external transfers that bypass expected time delays or spending limits
Evidence notes
NVD record published 2026-05-08, modified 2026-05-19. GitHub Security Advisory GHSA-9chc-gjfr-6hrq and commit fb6ef59d6c1385400e7acea7ae31fc6a473c3051 confirm fix. CVSS 4.0 vector indicates network attack vector with high integrity and availability impact. CWE-284 (Improper Access Control) and CWE-639 (Authorization Bypass Through User-Controlled Key) identified.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-42278 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-42278
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-42278 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-42278
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/UltraDAGcom/core/commit/fb6ef59d6c1385400e7acea7ae31fc6a473c3051
-
Source reference
Unverified legacy reference
URL: https://github.com/UltraDAGcom/core/security/advisories/GHSA-9chc-gjfr-6hrq
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.