-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 0xCERT Security Advisory 0xCERT-2026-0188 ============================================================ Advisory-ID: 0xCERT-2026-0188 Severity: Critical Published: 2026-10-06T19:18:13.500Z Updated: 2026-10-08T22:46:40.731Z Chains: n/a URL: https://www.0xcert.com/advisory/0xCERT-2026-0188 Title: CVE-2026-106511: MultiversX's multisig-improved (repository: mx-multisig-and-modules) reference i Summary - ------- MultiversX's multisig-improved (repository: mx-multisig-and-modules) reference implementation of their on-chain multisig smart contract system contains a vulnerability where a missing independent authorization check allows any account with the Proposer role to perform explicitly barred actions. This vulnerability allows the Proposer role to move funds alone, draining 100% of a contract's EGLD/ESDT balance in two transactions with zero signatures. Details - ------- Summary MultiversX's multisig-improved (repository: mx-multisig-and-modules) reference implementation of their on-chain multisig smart contract system contains a vulnerability where a missing independent authorization check allows any account with the Proposer role to perform explicitly barred actions. This vulnerability allows the Proposer role to move funds alone, draining 100% of a contract's EGLD/ESDT balance in two transactions with zero signatures. Severity Critical (CVSS 9.8), as scored by NVD. Weakness - - CWE-306 - - CWE-862 - - CWE-863 Recommended actions - - Check whether you run or depend on the affected component and version - - Apply the vendor's fix or mitigation from the references below Source & attribution This 0xCERT advisory summarises CVE-2026-106511 from the U.S. National Vulnerability Database: https://nvd.nist.gov/vuln/detail/CVE-2026-106511. Details may change; refer to the original source for the authoritative record. References - ---------- - - https://nvd.nist.gov/vuln/detail/CVE-2026-106511 - - https://gist.github.com/x01griax/c03f4be898dc55ccf3bab667c83c7312 - - https://github.com/multiversx/mx-multisig-and-modules - - https://gist.github.com/x01griax/c03f4be898dc55ccf3bab667c83c7312 Verify with the 0xCERT OpenPGP key: https://www.0xcert.com/pgp.asc Fingerprint: 5F94 3ED1 1E50 CF31 2128 C493 CCC7 D9EC 9415 723D -----BEGIN PGP SIGNATURE----- wrsEARYKAG0FgmrI9OwJEDe9Tbcr+ZxrRRQAAAAAABwAIHNhbHRAbm90YXRp b25zLm9wZW5wZ3Bqcy5vcmeh3KUwdgBRbdgLpWnVJL5KEkvd7D9o89jjlFaB NbF6cRYhBGCkkFZbJcT5QWu27ze9Tbcr+ZxrAAAERAEAyyvcK6RlbrpwYRSt OcTY/67STKL3/8TW0NVHomboHh8BAI6iGEGN0DOsFzBBZXMRrVrlAMSB2c4e Grnc/CgIY5cK =AP3Y -----END PGP SIGNATURE-----