PatchSiren

MultiversX Labs S.R.L. CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review MultiversX Labs S.R.L. CVE published 2026-10-06

CVE-2026-106511

A vulnerability in MultiversX's multisig-improved smart contract system allows a Proposer to perform barred actions, including draining 100% of a contract's EGLD/ESDT balance in two transactions with zero signatures. This issue requires immediate attention from defenders to prevent potential loss of funds and compromise of smart contract integrity. The vulnerability's impact is significant because it enab [truncated]