CVE-2026-100248
CVE-2026-100248 is a high-severity vulnerability with a CVSS 4.0 base score of 8.4. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-1025.
Key facts
- Severity: High (CVSS 4.0 base score 8.4)
- EPSS exploit prediction: 0% (33rd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-1025
- Published:
- Last modified:
Description
The Rattadan Cosmowarp smart contract before 56c6147 can have a comparison to an unintended value of current_admin.
Frequently asked questions
- What is CVE-2026-100248?
- The Rattadan Cosmowarp smart contract before 56c6147 can have a comparison to an unintended value of current_admin.
- How severe is CVE-2026-100248?
- CVE-2026-100248 has a CVSS 4.0 base score of 8.4, rated high severity.
- Is CVE-2026-100248 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (33rd percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-100248?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-100248 published?
- CVE-2026-100248 was published on 2026-09-25 and last updated on 2026-09-30.
References
- https://github.com/rattadan/Cosmowarp_Contract/blob/cc75c6f105ddae7627d878365637ebc279f4821d
- https://github.com/rattadan/Cosmowarp_Contract/blob/cc75c6f105ddae7627d878365637ebc279f4821d/asset_registry/src/contract.rs#L343
- https://github.com/rattadan/Cosmowarp_Contract/commit/56c6147ee613a6aaa157ecefe2f7bf0ad9084fa8
Other CWE-1025 vulnerabilities
- CVE-2025-71377 — High (CVSS 8.7): stoatchat (delta) versions before 20250210-1 (0.8.2) contain a logic error in the query messages route. When fetching…
- CVE-2026-9800 — High (CVSS 8.1): A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all…
- CVE-2026-40880 — High (CVSS 8.1): ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and zebra-consensus version 5.0.2, a…
- CVE-2026-29811 — High (CVSS 7.7): CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a…
- CVE-2023-54390 — High (CVSS 7.5): PocketMine-MP versions before 5.3.1 and 4.23.1 contain a denial of service vulnerability in LoginPacket JSON parsing…
- CVE-2026-75840 — High (CVSS 7.5): ArcadeDB before 26.8.1 contains an arbitrary file read vulnerability in the GraalVM JavaScript sandbox allowlist…