Skip to content
Latest alertgo-ethereum v1.17.8 security release fixes p2p DoS issues and a STUN-response node crash
0xCERT
All advisories
Critical0xCERT-2026-0188·

CVE-2026-106511: MultiversX's multisig-improved (repository: mx-multisig-and-modules) reference i

MultiversX's multisig-improved (repository: mx-multisig-and-modules) reference implementation of their on-chain multisig smart contract system contains a vulnerability where a missing independent authorization check allows any account with the Proposer role to perform explicitly barred actions. This vulnerability allows the Proposer role to move funds alone, draining 100% of a contract's EGLD/ESDT balance in two transactions with zero signatures.

Vuln-watch · relayed from the NVD / CVE program; see Source & attribution below

Summary

MultiversX's multisig-improved (repository: mx-multisig-and-modules) reference implementation of their on-chain multisig smart contract system contains a vulnerability where a missing independent authorization check allows any account with the Proposer role to perform explicitly barred actions. This vulnerability allows the Proposer role to move funds alone, draining 100% of a contract's EGLD/ESDT balance in two transactions with zero signatures.

Severity

Critical (CVSS 9.8), as scored by NVD.

Weakness

  • CWE-306
  • CWE-862
  • CWE-863

Recommended actions

  • Check whether you run or depend on the affected component and version
  • Apply the vendor's fix or mitigation from the references below

Source & attribution

This 0xCERT advisory summarises CVE-2026-106511 from the U.S. National Vulnerability Database: https://nvd.nist.gov/vuln/detail/CVE-2026-106511. Details may change; refer to the original source for the authoritative record.

OpenPGP-signed. The signed text of this advisory verifies against the 0xCERT key CCC7 D9EC 9415 723D.

Published 2026-10-06 · last updated 2026-10-08

curl -s https://www.0xcert.com/pgp.asc | gpg --import && curl -s https://www.0xcert.com/advisory/0xCERT-2026-0188/signed.txt | gpg --verify