PatchSiren cyber security CVE debrief
CVE-2026-82750 ZenHive CVE debrief
CVE-2026-82750 Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a large multiplier and to have the sponsor pay for EIP-7702 account delegations of the client's choosing. This vulnerability affects mpp versions from 0.2.0 before 0.16.1. The issue arises from the server's sponsorship of Tempo payments, where MPP.Methods.Tempo.FeePayerPolicy.measure/3 in lib/mpp/methods/tempo/fee_payer_policy.ex fails to read the aa_authorization_list field of the client-signed 0x76 envelope, leading to unauthorized gas cost inflation. Defenders should assess exposure, prioritize verification and remediation efforts, and review sponsored payment configurations to prevent similar attacks.
- Vendor
- ZenHive
- Product
- mpp
- CVSS
- HIGH 8.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-06
- Original CVE updated
- 2026-09-06
- Advisory published
- 2026-09-06
- Advisory updated
- 2026-09-06
Who should care
Defenders responsible for ZenHive mpp deployments, particularly those using sponsored payments, should assess exposure and prioritize verification and remediation efforts. They should review sponsored payment configurations to prevent similar gas cost inflation attacks and monitor for suspicious activity related to sponsored payments.
Why it matters
CVE-2026-82750 allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment, potentially leading to significant financial impacts and unauthorized use of sponsored payments.
- Potential for significant gas cost inflation
- Possible unauthorized use of sponsored payments for EIP-7702 account delegations
- Need for verification of affected versions and remediation efforts
Technical summary
The vulnerability is caused by improper validation of specified quantity in input in ZenHive mpp, which allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a large multiplier and to have the sponsor pay for EIP-7702 account delegations of the client's choosing. This can lead to significant financial impacts and unauthorized use of sponsored payments. The vulnerability affects mpp versions from 0.2.0 before 0.16.1.
Defensive priority
Defenders should prioritize verifying and upgrading to mpp version 0.16.1 or later, and review sponsored payment configurations to prevent similar gas cost inflation attacks.
Recommended defensive actions
- Verify and upgrade to mpp version 0.16.1 or later
- Review sponsored payment configurations to prevent similar gas cost inflation attacks
- Monitor for suspicious activity related to sponsored payments
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
Evidence notes
The CVE record and source references provide details on the vulnerability, including its description, CVSS score, and affected versions. The vulnerability allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a large multiplier and to have the sponsor pay for EIP-7702 account delegations of the client's choosing. Defenders should verify the affected versions and review sponsored payment configurations to prevent similar gas cost inflation attacks. The CVE Program record and NVD detail page provide additional information on the vulnerability. The source references also provide additional context on the vulnerability and its impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-82750 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-82750
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-82750 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-82750
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://cna.erlef.org/cves/CVE-2026-82750.html
6b3ad84c-e1a6-4bf7-a703-f496b71e49db
-
Source reference
Unverified legacy reference
URL: https://github.com/ZenHive/mpp/commit/0482572b47e1ffe1537ab80ab613d47b92833c2d
6b3ad84c-e1a6-4bf7-a703-f496b71e49db
-
Source reference
Unverified legacy reference
URL: https://github.com/ZenHive/mpp/security/advisories/GHSA-5qrp-r24c-w6jr
6b3ad84c-e1a6-4bf7-a703-f496b71e49db
-
Source reference
Unverified legacy reference
URL: https://osv.dev/vulnerability/EEF-CVE-2026-82750
6b3ad84c-e1a6-4bf7-a703-f496b71e49db
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.