---
id: CVE-2026-106511
title: >-
  MultiversX's multisig-improved (repository: mx-multisig-and-modules) reference
  implementation of their on-chain multisig smart contract system contains a
  vulnerability where a missing independent authorization check allows any
  account wi…
summary: >-
  MultiversX's multisig-improved (repository: mx-multisig-and-modules) reference
  implementation of their on-chain multisig smart contract system contains a
  vulnerability where a missing independent authorization check allows any
  account wi…
severity: none
cwe:
  - CWE-862
  - CWE-863
  - CWE-306
vendor: MultiversX Labs S.R.L.
product: multisig-improved
affected:
  - multisig-improved GitHub commit 2e6dbea40f9b8ac165572a9efd4304804762a299
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T20:06:12.743'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-106511'
references:
  - url: 'https://github.com/multiversx/mx-multisig-and-modules'
    label: cret@cert.org
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T19:13:33.852Z'
---

## Overview

MultiversX's multisig-improved (repository: mx-multisig-and-modules) reference implementation of their on-chain multisig smart contract system contains a vulnerability where a missing independent authorization check allows any account with the Proposer role to perform explicitly barred actions. This vulnerability allows the Proposer role to move funds alone, draining 100% of a contract's EGLD/ESDT balance in two transactions with zero signatures.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
