High0xCERT-2026-0181·
CVE-2026-100248: The Rattadan Cosmowarp smart contract
The Rattadan Cosmowarp smart contract before 56c6147 can have a comparison to an unintended value of current_admin.
Vuln-watch · relayed from the NVD / CVE program; see Source & attribution below
Summary
The Rattadan Cosmowarp smart contract before 56c6147 can have a comparison to an unintended value of current_admin.
Severity
High (CVSS 8.4), as scored by NVD.
Weakness
- CWE-1025
Recommended actions
- Check whether you run or depend on the affected component and version
- Apply the vendor's fix or mitigation from the references below
Source & attribution
This 0xCERT advisory summarises CVE-2026-100248 from the U.S. National Vulnerability Database: https://nvd.nist.gov/vuln/detail/CVE-2026-100248. Details may change; refer to the original source for the authoritative record.
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-100248
- https://github.com/rattadan/Cosmowarp_Contract/blob/cc75c6f105ddae7627d878365637ebc279f4821d
- https://github.com/rattadan/Cosmowarp_Contract/blob/cc75c6f105ddae7627d878365637ebc279f4821d/asset_registry/src/contract.rs#L343
- https://github.com/rattadan/Cosmowarp_Contract/commit/56c6147ee613a6aaa157ecefe2f7bf0ad9084fa8
OpenPGP-signed. The signed text of this advisory verifies against the 0xCERT key CCC7 D9EC 9415 723D.
Published 2026-09-25 · last updated 2026-10-08
curl -s https://www.0xcert.com/pgp.asc | gpg --import && curl -s https://www.0xcert.com/advisory/0xCERT-2026-0181/signed.txt | gpg --verify