CVE-2026-67581: CWE-294 Authentication Bypass by Capture-replay in ZenHive mpp
Authentication Bypass by Capture-replay in ZenHive mpp allows an unauthenticated remote client to obtain paid resources by resubmitting one settled on-chain transfer. MPP.Methods.EVM.verify/2 accepts a transaction-hash credential and matches a transfer purely on token, to and amount (ERC-20) or to and value (native). It binds the proof neither to the challenge being verified nor to any record of prior use, and the generic MPP.Plug dedup store keys on challenge.id, which is regenerated for every 402 response. On a static-price route, a single historical transfer matching the charge therefore satisfies an unbounded number of later charges, including transfers an attacker can read off a public block explorer. This issue affects mpp: from 0.3.0 before 0.6.3.
AI Analysis
Technical Summary
The vulnerability in ZenHive mpp (versions 0.3.0 through before 0.6.3) involves the MPP.Methods.EVM.verify/2 function, which accepts a transaction hash as credential and validates a transfer based solely on token, recipient, and amount parameters. It does not bind the proof to the specific verification challenge nor maintain a record of prior use. The generic MPP.Plug deduplication store keys on challenge.id, which is regenerated for every 402 response, allowing reuse of a single historical transfer to satisfy multiple later charges. Since transfers are publicly visible on block explorers, an attacker can capture and replay these to bypass authentication and gain paid resources without authorization.
Potential Impact
An unauthenticated remote attacker can bypass authentication controls by replaying a previously settled on-chain transfer transaction. This allows the attacker to obtain paid resources multiple times without making new payments, leading to unauthorized resource consumption and potential financial loss for the service provider.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should consider implementing additional verification mechanisms that bind proofs to specific challenges and track prior use to prevent replay attacks. Monitoring for unusual repeated use of the same transaction hashes may help detect exploitation attempts.
CVE-2026-67581: CWE-294 Authentication Bypass by Capture-replay in ZenHive mpp
Description
Authentication Bypass by Capture-replay in ZenHive mpp allows an unauthenticated remote client to obtain paid resources by resubmitting one settled on-chain transfer. MPP.Methods.EVM.verify/2 accepts a transaction-hash credential and matches a transfer purely on token, to and amount (ERC-20) or to and value (native). It binds the proof neither to the challenge being verified nor to any record of prior use, and the generic MPP.Plug dedup store keys on challenge.id, which is regenerated for every 402 response. On a static-price route, a single historical transfer matching the charge therefore satisfies an unbounded number of later charges, including transfers an attacker can read off a public block explorer. This issue affects mpp: from 0.3.0 before 0.6.3.
CVSS v4.0
Score 8.7high
Affected software
ZenHive
mpp
ZenHive
mpp
cpe:2.3:a:ZenHive:mpp:*:*:*:*:*:*:*:*Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in ZenHive mpp (versions 0.3.0 through before 0.6.3) involves the MPP.Methods.EVM.verify/2 function, which accepts a transaction hash as credential and validates a transfer based solely on token, recipient, and amount parameters. It does not bind the proof to the specific verification challenge nor maintain a record of prior use. The generic MPP.Plug deduplication store keys on challenge.id, which is regenerated for every 402 response, allowing reuse of a single historical transfer to satisfy multiple later charges. Since transfers are publicly visible on block explorers, an attacker can capture and replay these to bypass authentication and gain paid resources without authorization.
Potential Impact
An unauthenticated remote attacker can bypass authentication controls by replaying a previously settled on-chain transfer transaction. This allows the attacker to obtain paid resources multiple times without making new payments, leading to unauthorized resource consumption and potential financial loss for the service provider.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should consider implementing additional verification mechanisms that bind proofs to specific challenges and track prior use to prevent replay attacks. Monitoring for unusual repeated use of the same transaction hashes may help detect exploitation attempts.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- EEF
- Date Reserved
- 2026-08-18T10:30:01.759Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a85eb32acd9273b49667256
Added to database: 08/19/2026, 17:43:14 UTC
Last enriched: 08/19/2026, 17:52:20 UTC
Last updated: 10/03/2026, 14:46:09 UTC
Views: 79
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.