Description
The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission attribution. A signed account can supply an arbitrary registered `channel_id` when minting tokens without verifying that the caller is authorized to mint on behalf of that channel. This allows an attacker to inflate a channel's recorded mint volume and cause protocol commission payments to be disproportionately distributed to that channel during commission settlement.
Published: 2026-09-08
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized commission diversion
Action: Apply patch
AI Analysis

Impact

The vulnerability is present in the vtoken-minting and slpx pallets of Bifrost, allowing a signed account to provide any registered channel_id when minting tokens without verifying that the caller is authorized to mint on that channel. This permits an attacker to inflate the mint volume recorded for a specific channel, causing the protocol’s commission settlement to over‑reward that channel and divert protocol revenue.

Affected Systems

The affected product is Bifrost from Bitfrost.io. The issue applies to all releases that include the vtoken‑minting and slpx pallets without the required authorization checks, and no specific version range is provided.

Risk and Exploitability

The vulnerability carries a CVSS score of 9.1, indicating critical severity. The EPSS score of less than 1% suggests a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Attackers need a legitimate signed account and a known channel_id to inflate mint volumes, which can lead to significant financial loss through commission diversion. Because the flaw lacks host or network‑based checks, the exploitation is limited to insiders or compromised accounts with tokens.

Generated by OpenCVE AI on September 11, 2026 at 07:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest published Bifrost release that includes the fix for channel commission attribution.
  • Ensure that the vtoken‑minting and slpx pallets enforce explicit ownership checks and restrict minting operations to the rightful channel owner only.
  • Monitor and alert on unusually high mint volumes per channel, and audit commission settlement logs for anomalous activity.

Generated by OpenCVE AI on September 11, 2026 at 07:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Thu, 10 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639
CWE-862
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Bitfrost.io
Bitfrost.io bifrost
Vendors & Products Bitfrost.io
Bitfrost.io bifrost

Tue, 08 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 08 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission attribution. A signed account can supply an arbitrary registered `channel_id` when minting tokens without verifying that the caller is authorized to mint on behalf of that channel. This allows an attacker to inflate a channel's recorded mint volume and cause protocol commission payments to be disproportionately distributed to that channel during commission settlement.
Title Bifrost Unauthorized Channel Commission Attribution Allows Commission Diversion
References

Subscriptions

Bitfrost.io Bifrost
cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2026-09-10T18:27:49.910Z

Reserved: 2026-09-08T14:43:37.022Z

Link: CVE-2026-86840

cve-icon Vulnrichment

Updated: 2026-09-10T18:27:40.615Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T16:18:37.597

Modified: 2026-09-10T19:17:36.980

Link: CVE-2026-86840

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T07:45:07Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key

  • CWE-862

    Missing Authorization