CVE-2026-87119
📛 CVE Title
mpp Tempo subscription key authorization is not bound to the issuing challenge, allowing a captured activation credential to be replayed
Description
Authentication Bypass by Capture-replay in ZenHive mpp allows an attacker holding a captured subscription activation credential to charge the payer repeatedly. The payer signs a Tempo KeyAuthorization over the chain id, key type, key id, expiry, limits and scopes only, with nothing tying it to the challenge that prompted it. MPP.Methods.Tempo.KeyAuthorization.verify/3 in lib/mpp/methods/tempo/key_authorization.ex pins each of those signed fields against the subscription request, and the access key it pins is a static per-endpoint server key, so one signed authorization verifies against every challenge the server issues for the same subscription terms. MPP.Methods.Tempo.Subscription.activate/4 deduplicates activations by challenge id, so presenting the captured credential under a fresh challenge produces a different dedup key, claim_activation succeeds, and the subscription transaction is built and broadcast again. Each replay charges the payer's wallet a new first-period settlement and re-authorizes the server key, bounded only by the subscription expiry and the chain's own semantics for re-installing an existing key. This issue affects mpp: from 0.14.0 before 0.16.2.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- EEF
- CVSS severity
- HIGH
- CVSS score
- 8.2 / 10
- CVSS vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N- Effective score
- 8.2 / 10 HIGH source: CNA overview
- CWE(s)
-
CWE-294 - Reserved
- 2026-09-11
- Published
- 2026-09-22 11:16 UTC
- Last updated
- 2026-09-22 12:02 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/87xxx/CVE-2026-87119.json
- Linked Threat
- CVE-2026-87119 — mpp Tempo subscription key authorization is not bound to the issuing challenge, allowing a captured activation credential to be replayed
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-09-22 12:17:14 UTC
- NVD last modified
- 2026-09-22 19:09:32 UTC
NVD / KEV / EPSS data refreshed 2026-09-23 02:35 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-84361 - Assigner
- EEF
- Published
- Sep 22, 2026, 11:16:56 AM
- Updated
- Sep 22, 2026, 12:02:31 PM
- EUVD base score (CVSS 4.0)
-
8.2 / 10
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N - EUVD-reported EPSS
- 0.0000
- Vendors
- ZenHive
- Products
-
mpp (db464dfa9a86ccda58f0827101f6da6bd8aafa78 <4b6eaec02af0e8485cfb4ff68f467d075ed5dd6f)mpp (0.14.0 <0.16.2)
- Aliases
-
GHSA-h97r-55w6-6rfg
ENISA description: Authentication Bypass by Capture-replay in ZenHive mpp allows an attacker holding a captured subscription activation credential to charge the payer repeatedly. The payer signs a Tempo KeyAuthorization over the chain id, key type, key id, expiry, limits and scopes only, with nothing tying it to the challenge that prompted it. MPP.Methods.Tempo.KeyAuthorization.verify/3 in lib/mpp/methods/tempo/key_authorization.ex pins each of those signed fields against the subscription request, and the access key it pins is a static per-endpoint server key, so one signed authorization verifies against every challenge the server issues for the same subscription terms. MPP.Methods.Tempo.Subscription.activate/4 deduplicates activations by challenge id, so presenting the captured credential under a fresh challenge produces a different dedup key, claim_activation succeeds, and the subscription transaction is built and broadcast again. Each replay charges the payer's wallet a new first-period settlement and re-authorizes the server key, bounded only by the subscription expiry and the chain's own semantics for re-installing an existing key. This issue affects mpp: from 0.14.0 before 0.16.2.
EUVD references (5)
- https://github.com/ZenHive/mpp/security/advisories/GHSA-p9fv-9w58-95x2
- https://cna.erlef.org/cves/CVE-2026-87119.html
- https://osv.dev/vulnerability/EEF-CVE-2026-87119
- https://github.com/ZenHive/mpp/commit/db464dfa9a86ccda58f0827101f6da6bd8aafa78
- https://github.com/ZenHive/mpp/commit/4b6eaec02af0e8485cfb4ff68f467d075ed5dd6f
Affected products (2)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| ZenHive | mpp |
0.14.0 (affected)
|
— |
| ZenHive | mpp |
db464dfa9a86ccda58f0827101f6da6bd8aafa78 (affected)
|
— |
Vendor references (5)
References embedded in the original CVE record by the assigning CNA.
- GitHub Advisory relatedvendor-advisory
- EEF CNA record for CVE-2026-87119 related
- OSV record EEF-CVE-2026-87119 related
- Introducing commit db464df in ZenHive/mpp related
- Fix commit 4b6eaec in ZenHive/mpp patch
Web references (0)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
No web references attached yet.
NVD-tagged references (5)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://cna.erlef.org/cves/CVE-2026-87119.html 6b3ad84c-e1a6-4bf7-a703-f496b71e49db
- https://github.com/ZenHive/mpp/commit/4b6eaec02af0e8485cfb4ff68f467d075ed5dd6f 6b3ad84c-e1a6-4bf7-a703-f496b71e49db
- https://github.com/ZenHive/mpp/commit/db464dfa9a86ccda58f0827101f6da6bd8aafa78 6b3ad84c-e1a6-4bf7-a703-f496b71e49db
- https://github.com/ZenHive/mpp/security/advisories/GHSA-p9fv-9w58-95x2 6b3ad84c-e1a6-4bf7-a703-f496b71e49db
- https://osv.dev/vulnerability/EEF-CVE-2026-87119 6b3ad84c-e1a6-4bf7-a703-f496b71e49db
Remediations (10)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:blog.qualys.com
The August 2026 Microsoft Patch Tuesday release delivers security fixes for vulnerabilities affecting a wide range of Microsoft products and services.
2026-09-23 15:14 UTC -
web:msrc.microsoft.com
The Microsoft Security Response Center (MSRC) investigates all reports of security vulnerabilities affecting Microsoft products and services, and provides the information here as part of the ongoing effort to help you manage security risks and help keep your systems protected.
2026-09-23 15:14 UTC -
web:sec.cloudapps.cisco.com
On September 16, 2026 , the Cisco Product Security Incident Response Team (PSIRT) published the advisories that are listed in the following tables. To remediate these vulnerabilities, Cisco strongly recommends that customers upgrade to the fixed software that is indicated in the advisories. For more information about changes in Cisco PSIRT vulnerability disclosure, see Strengthening the ...
2026-09-23 15:14 UTC -
web:senserva.com
Every Microsoft security patch (KB) and the CVEs it fixes, with severity, CVSS, and CISA KEV status. Cross-linked to the CVE reference.
2026-09-23 15:14 UTC -
web:support.microsoft.com
This out-of-band (OOB) update for Windows 11, version 25H2 and Windows 11, version 24H2 (KB5121768) is cumulative. It includes all improvements from previous security and non-security updates, along with an additional fix . Improvements This OOB update includes the following improvement: [System Performance] This update addresses an issue affecting a limited number of devices with an Intel ...
2026-09-23 15:14 UTC -
web:support.sap.com
SAP security Patch Day Bulletin This post shares the information on security notes that remediate vulnerabilities discovered in SAP products. SAP strongly recommends that the customer visits the support portal and applies patches on priority to protect their SAP landscape. On 9th of June 2026 , SAP security patch day saw the release of 15 new security notes.
2026-09-23 15:14 UTC -
web:windowsforum.com
A newly disclosed flaw in Windows Admin Center (WAC) creates a dangerous escalation path from low‑privileged, authenticated users to the administrative context that runs the management plane — a weakness that demands immediate action from anyone who runs WAC in production. The vulnerability, tracked as CVE‑2026‑26119 and scored at CVSS 8.8, stems from an improper authentication ...
2026-09-23 15:14 UTC -
web:www.computerworld.com
August's Patch Tuesday is a big one: 751 fixes, an exploited WinSock flaw and plenty of critical Windows, Office and Exchange issues.
2026-09-23 15:14 UTC -
web:www.dell.com
Cloud Disaster Recovery remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.
2026-09-23 15:14 UTC -
web:www.veeam.com
When a vulnerability is identified, our team promptly develops a patch to address and mitigate the risk. In line with our dedication to transparency, we publicly disclose the vulnerability and provide detailed mitigation information.
2026-09-23 15:14 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2026-87119.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-87119",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-22T12:02:12.184296Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T12:02:31.484Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://repo.hex.pm",
"cpes": [
"cpe:2.3:a:ZenHive:mpp:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"modules": [
"'Elixir.MPP.Methods.Tempo.KeyAuthorization'",
"'Elixir.MPP.Methods.Tempo.Subscription'"
],
"packageName": "mpp",
"packageURL": "pkg:hex/mpp",
"product": "mpp",
"programFiles": [
"lib/mpp/methods/tempo/key_authorization.ex",
"lib/mpp/methods/tempo/subscription.ex"
],
"programRoutines": [
{
"name": "'Elixir.MPP.Methods.Tempo.KeyAuthorization':verify/3"
},
{
"name": "'Elixir.MPP.Methods.Tempo.KeyAuthorization':wallet_params/2"
},
{
"name": "'Elixir.MPP.Methods.Tempo.KeyAuthorization':from_rpc/1"
},
{
"name": "'Elixir.MPP.Methods.Tempo.Subscription':verify/2"
}
],
"repo": "https://github.com/ZenHive/mpp",
"vendor": "ZenHive",
"versions": [
{
"lessThan": "0.16.2",
"status": "affected",
"version": "0.14.0",
"versionType": "semver"
}
]
},
{
"collectionURL": "https://github.com",
"cpes": [
"cpe:2.3:a:ZenHive:mpp:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"modules": [
"'Elixir.MPP.Methods.Tempo.KeyAuthorization'",
"'Elixir.MPP.Methods.Tempo.Subscription'"
],
"packageName": "zenhive/mpp",
"packageURL": "pkg:github/zenhive/mpp",
"product": "mpp",
"programFiles": [
"lib/mpp/methods/tempo/key_authorization.ex",
"lib/mpp/methods/tempo/subscription.ex"
],
"programRoutines": [
{
"name": "'Elixir.MPP.Methods.Tempo.KeyAuthorization':verify/3"
},
{
"name": "'Elixir.MPP.Methods.Tempo.KeyAuthorization':wallet_params/2"
},
{
"name": "'Elixir.MPP.Methods.Tempo.KeyAuthorization':from_rpc/1"
},
{
"name": "'Elixir.MPP.Methods.Tempo.Subscription':verify/2"
}
],
"repo": "https://github.com/ZenHive/mpp",
"vendor": "ZenHive",
"versions": [
{
"lessThan": "4b6eaec02af0e8485cfb4ff68f467d075ed5dd6f",
"status": "affected",
"version": "db464dfa9a86ccda58f0827101f6da6bd8aafa78",
"versionType": "git"
}
]
}
],
"configurations": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "<p>Only deployments offering Tempo subscriptions are affected, which requires <code>subscription_access_key_private_key</code> in the Tempo <code>method_config</code>. Exploitation further requires the attacker to have obtained a payer's signed activation credential, in transit over a hop that is not TLS-protected or at rest in a log, an intermediary, or a client retry buffer.</p>"
},
{
"base64": false,
"type": "text/markdown",
"value": "Only deployments offering Tempo subscriptions are affected, which requires `subscription_access_key_private_key` in the Tempo `method_config`. Exploitation further requires the attacker to have obtained a payer's signed activation credential, in transit over a hop that is not TLS-protected or at rest in a log, an intermediary, or a client retry buffer."
}
],
"value": "Only deployments offering Tempo subscriptions are affected, which requires subscription_access_key_private_key in the Tempo method_config. Exploitation further requires the attacker to have obtained a payer's signed activation credential, in transit over a hop that is not TLS-protected or at rest in a log, an intermediary, or a client retry buffer."
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ZenHive:mpp:*:*:*:*:*:*:*:*",
"versionEndExcluding": "0.16.2",
"versionStartIncluding": "0.14.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "E.FU"
},
{
"lang": "en",
"type": "remediation developer",
"value": "E.FU"
},
{
"lang": "en",
"type": "coordinator",
"value": "Jonatan M\u00e4nnchen / EEF"
}
],
"dateAssigned": "2026-09-15T15:20:31.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "<p>Authentication Bypass by Capture-replay in ZenHive mpp allows an attacker holding a captured subscription activation credential to charge the payer repeatedly.</p>\n<p>The payer signs a Tempo <code>KeyAuthorization</code> over the chain id, key type, key id, expiry, limits and scopes only, with nothing tying it to the challenge that prompted it. <code>MPP.Methods.Tempo.KeyAuthorization.verify/3</code> in <code>lib/mpp/methods/tempo/key_authorization.ex</code> pins each of those signed fields against the subscription request, and the access key it pins is a static per-endpoint server key, so one signed authorization verifies against every challenge the server issues for the same subscription terms. <code>MPP.Methods.Tempo.Subscription.activate/4</code> deduplicates activations by challenge id, so presenting the captured credential under a fresh challenge produces a different dedup key, <code>claim_activation</code> succeeds, and the subscription transaction is built and broadcast again. Each replay charges the payer's wallet a new first-period settlement and re-authorizes the server key, bounded only by the subscription expiry and the chain's own semantics for re-installing an existing key.</p>\n<p>This issue affects mpp: from 0.14.0 before 0.16.2.</p>"
},
{
"base64": false,
"type": "text/markdown",
"value": "Authentication Bypass by Capture-replay in ZenHive mpp allows an attacker holding a captured subscription activation credential to charge the payer repeatedly.\n\nThe payer signs a Tempo `KeyAuthorization` over the chain id, key type, key id, expiry, limits and scopes only, with nothing tying it to the challenge that prompted it. `MPP.Methods.Tempo.KeyAuthorization.verify/3` in `lib/mpp/methods/tempo/key_authorization.ex` pins each of those signed fields against the subscription request, and the access key it pins is a static per-endpoint server key, so one signed authorization verifies against every challenge the server issues for the same subscription terms. `MPP.Methods.Tempo.Subscription.activate/4` deduplicates activations by challenge id, so presenting the captured credential under a fresh challenge produces a different dedup key, `claim_activation` succeeds, and the subscription transaction is built and broadcast again. Each replay charges the payer's wallet a new first-period settlement and re-authorizes the server key, bounded only by the subscription expiry and the chain's own semantics for re-installing an existing key.\n\nThis issue affects mpp: from 0.14.0 before 0.16.2."
}
],
"value": "Authentication Bypass by Capture-replay in ZenHive mpp allows an attacker holding a captured subscription activation credential to charge the payer repeatedly.\n\nThe payer signs a Tempo KeyAuthorization over the chain id, key type, key id, expiry, limits and scopes only, with nothing tying it to the challenge that prompted it. MPP.Methods.Tempo.KeyAuthorization.verify/3 in lib/mpp/methods/tempo/key_authorization.ex pins each of those signed fields against the subscription request, and the access key it pins is a static per-endpoint server key, so one signed authorization verifies against every challenge the server issues for the same subscription terms. MPP.Methods.Tempo.Subscription.activate/4 deduplicates activations by challenge id, so presenting the captured credential under a fresh challenge produces a different dedup key, claim_activation succeeds, and the subscription transaction is built and broadcast again. Each replay charges the payer's wallet a new first-period settlement and re-authorizes the server key, bounded only by the subscription expiry and the chain's own semantics for re-installing an existing key.\n\nThis issue affects mpp: from 0.14.0 before 0.16.2."
}
],
"impacts": [
{
"capecId": "CAPEC-60",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "<p>An attacker who obtains a payer's subscription activation credential (from a non-TLS hop, a log, a compromised intermediary, or the client's own retry buffer) can present it under fresh challenges to settle repeated first-period charges against that payer's wallet and re-authorize the server's access key. The payer bears the on-chain cost, limited only by the per-period subscription limit and the subscription expiry.</p>"
},
{
"base64": false,
"type": "text/markdown",
"value": "An attacker who obtains a payer's subscription activation credential (from a non-TLS hop, a log, a compromised intermediary, or the client's own retry buffer) can present it under fresh challenges to settle repeated first-period charges against that payer's wallet and re-authorize the server's access key. The payer bears the on-chain cost, limited only by the per-period subscription limit and the subscription expiry."
}
],
"value": "An attacker who obtains a payer's subscription activation credential (from a non-TLS hop, a log, a compromised intermediary, or the client's own retry buffer) can present it under fresh challenges to settle repeated first-period charges against that payer's wallet and re-authorize the server's access key. The payer bears the on-chain cost, limited only by the per-period subscription limit and the subscription expiry."
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "HIGH",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 8.2,
"baseSeverity": "HIGH",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-294",
"description": "CWE-294 Authentication Bypass by Capture-replay",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T11:16:56.232Z",
"orgId": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
"shortName": "EEF"
},
"references": [
{
"name": "GitHub Advisory",
"tags": [
"related",
"vendor-advisory"
],
"url": "https://github.com/ZenHive/mpp/security/advisories/GHSA-p9fv-9w58-95x2"
},
{
"name": "EEF CNA record for CVE-2026-87119",
"tags": [
"related"
],
"url": "https://cna.erlef.org/cves/CVE-2026-87119.html"
},
{
"name": "OSV record EEF-CVE-2026-87119",
"tags": [
"related"
],
"url": "https://osv.dev/vulnerability/EEF-CVE-2026-87119"
},
{
"name": "Introducing commit db464df in ZenHive/mpp",
"tags": [
"related"
],
"url": "https://github.com/ZenHive/mpp/commit/db464dfa9a86ccda58f0827101f6da6bd8aafa78"
},
{
"name": "Fix commit 4b6eaec in ZenHive/mpp",
"tags": [
"patch"
],
"url": "https://github.com/ZenHive/mpp/commit/4b6eaec02af0e8485cfb4ff68f467d075ed5dd6f"
}
],
"source": {
"discovery": "INTERNAL"
},
"title": "mpp Tempo subscription key authorization is not bound to the issuing challenge, allowing a captured activation credential to be replayed"
}
},
"cveMetadata": {
"assignerOrgId": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
"assignerShortName": "EEF",
"cveId": "CVE-2026-87119",
"datePublished": "2026-09-22T11:16:56.232Z",
"dateReserved": "2026-09-11T18:00:02.032Z",
"dateUpdated": "2026-09-22T12:02:31.484Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}