Anchor: Program<'info, System> is not properly validated
Anchor: Program<'info, System> is not properly validated. An logic error causes anchor programs to accept any program id when requiring the system program id, causing false assumptions resulting in potential arbitrary cpi in programs that invoke system program instructions.
Vuln-watch · relayed from the GitHub Advisory Database; see Source & attribution below
Summary
An logic error causes anchor programs to accept any program id when requiring the system program id, causing false assumptions resulting in potential arbitrary cpi in programs that invoke system program instructions.
Affected
- anchor-lang (rust) >= 1.0.0, < 1.0.2 — fixed in 1.0.2
Severity
High, as rated by the upstream advisory.
Recommended actions
- Upgrade anchor-lang to 1.0.2 or later
Source & attribution
This 0xCERT advisory summarises GHSA-c6rc-8jpp-2fgc / CVE-2026-45137 from the GitHub Advisory Database, credited upstream to Matthias1590: https://github.com/advisories/GHSA-c6rc-8jpp-2fgc. Details may change; refer to the original source for the authoritative record.
References
- https://github.com/advisories/GHSA-c6rc-8jpp-2fgc
- CVE-2026-45137
- https://github.com/solana-foundation/anchor/security/advisories/GHSA-c6rc-8jpp-2fgc
- https://github.com/solana-foundation/anchor/releases/tag/v1.0.2
- https://github.com/otter-sec/anchor/security/advisories/GHSA-c6rc-8jpp-2fgc
- https://rustsec.org/advisories/RUSTSEC-2026-0144.html
- https://nvd.nist.gov/vuln/detail/CVE-2026-45137
OpenPGP-signed. The signed text of this advisory verifies against the 0xCERT key CCC7 D9EC 9415 723D.
Published 2026-05-13 · last updated 2026-10-08
curl -s https://www.0xcert.com/pgp.asc | gpg --import && curl -s https://www.0xcert.com/advisory/0xCERT-2026-0197/signed.txt | gpg --verify