MultiversX's multisig-improved (repository: mx-multisig-and-modules) reference implementation of their on-chain multisig smart contract system contains a vulnerability where a missing independent authorization check allows any account with the Proposer role to perform explicitly barred actions. This vulnerability allows the Proposer role to move funds alone, draining 100% of a contract's EGLD/ESDT balance in two transactions with zero signatures.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://github.com/multiversx/mx-multisig-and-modules |
|
History
Tue, 06 Oct 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MultiversX's multisig-improved (repository: mx-multisig-and-modules) reference implementation of their on-chain multisig smart contract system contains a vulnerability where a missing independent authorization check allows any account with the Proposer role to perform explicitly barred actions. This vulnerability allows the Proposer role to move funds alone, draining 100% of a contract's EGLD/ESDT balance in two transactions with zero signatures. | |
| Title | CVE-2026-106511 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2026-10-06T18:52:33.825Z
Reserved: 2026-10-06T18:47:59.209Z
Link: CVE-2026-106511
No data.
Status : Deferred
Published: 2026-10-06T19:18:13.500
Modified: 2026-10-06T20:06:12.743
Link: CVE-2026-106511
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.