{"id":"CVE-2026-106511","title":"MultiversX's multisig-improved (repository: mx-multisig-and-modules) reference implementation of their on-chain multisig smart contract system contains a vulnerability where a missing independent authorization check allows any account wi…","summary":"MultiversX's multisig-improved (repository: mx-multisig-and-modules) reference implementation of their on-chain multisig smart contract system contains a vulnerability where a missing independent authorization check allows any account wi…","severity":"none","cwe":["CWE-862","CWE-863","CWE-306"],"vendor":"MultiversX Labs S.R.L.","product":"multisig-improved","affected":["multisig-improved GitHub commit 2e6dbea40f9b8ac165572a9efd4304804762a299"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T20:06:12.743","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-106511","references":[{"url":"https://github.com/multiversx/mx-multisig-and-modules","label":"cret@cert.org"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T19:13:33.852Z","slug":"CVE-2026-106511","body":"## Overview\n\nMultiversX's multisig-improved (repository: mx-multisig-and-modules) reference implementation of their on-chain multisig smart contract system contains a vulnerability where a missing independent authorization check allows any account with the Proposer role to perform explicitly barred actions. This vulnerability allows the Proposer role to move funds alone, draining 100% of a contract's EGLD/ESDT balance in two transactions with zero signatures.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}