CVE-2026-86840Critical· 9.1▾ AbyssalPoC availableThe `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission attribution. A signed account can supply an arbitrary registered `channel_id` when minting tokens without verifying …
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 50.1 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 10.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.1%
0.1% → 0.2%
9.1 → —
critical → none
Exploit / PoC code exists
— → 9.1
none → critical
9.1 → —
critical → none
— → 9.1
none → critical
The vtoken-minting and slpx pallets in Bifrost contain an improper authorization vulnerability in channel commission attribution. A signed account can supply an arbitrary registered channel_id when minting tokens without verifying that the caller is authorized to mint on behalf of that channel. This allows an attacker to inflate a channel's recorded mint volume and cause protocol commission payments to be disproportionately distributed to that channel during commission settlement.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-54671High· 8.8WeGIA is a web manager for charitable institutions
CVE-2026-53546Critical· 9.6Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities
CVE-2026-53769Medium· 6.5Avo is a framework to create admin panels for Ruby on Rails apps
CVE-2026-18121Medium· 6.3Concrete CMS 9.5.2 and below is vulnerable to an authorization bypass (IDOR) because the frontend calendar lightbox endpoint (/ccm/calendar/view_event/{bID}/{occurrence_id}) does not verify that the caller is permitted to view the calend…
CVE-2026-55178High· 7.5GeoLens is a self-hosted geospatial data catalog with semantic search, OGC and STAC APIs, and a map builder
CVE-2026-16105Medium· 4.9A flaw was found in the RoleContainerResource component of Keycloak