CVE-2026-82406
CVE-2026-82406 is a high-severity vulnerability with a CVSS 4.0 base score of 7.1. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-841.
Key facts
- Severity: High (CVSS 4.0 base score 7.1)
- EPSS exploit prediction: 0% (25th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-841
- Published:
- Last modified:
Description
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the native marketplace function core/kapp/market/market.go Buy does not check IsClaimed before accepting a bid. A seller can use the Claim seller-accept branch to settle a resting-bid auction while leaving the claimed order loadable with a future EndTime and stale CurrentBid and CurrentBidder values. A later bidder can submit a higher bid, be debited, and cause the previous bidder to receive a refund even though the NFT has already been delivered. Because Claim and CancelOrder reject the later bidder when IsClaimed is true, the later bidder cannot obtain the NFT or recover the funds. This issue is fixed in version 1.7.20.
Frequently asked questions
- What is CVE-2026-82406?
- Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the native marketplace function core/kapp/market/market.go Buy does not check IsClaimed before accepting a bid. A seller can use the Claim seller-accept branch to settle a resting-bid auction while leaving the claimed order loadable with a future EndTime and stale CurrentBid and CurrentBidder values. A later bidder can submit a higher bid, be debited, and cause the previous bidder to receive a refund even though the NFT has already been delivered. Because Claim and CancelOrder reject the later bidder when IsClaimed is true, the later bidder cannot obtain the NFT or recover the funds. This issue is fixed in version 1.7.20.
- How severe is CVE-2026-82406?
- CVE-2026-82406 has a CVSS 4.0 base score of 7.1, rated high severity.
- Is CVE-2026-82406 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (25th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-82406?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-82406 published?
- CVE-2026-82406 was published on 2026-09-23 and last updated on 2026-09-24.
References
- https://github.com/klever-io/klever-go/commit/063bb3ed98f9a84a4b1f7286680613a5fc3c91b2
- https://github.com/klever-io/klever-go/pull/16
- https://github.com/klever-io/klever-go/releases/tag/v1.7.20
- https://github.com/klever-io/klever-go/security/advisories/GHSA-26r5-4mm2-px5c
Other CWE-841 vulnerabilities
- CVE-2026-3130 — Critical (CVSS 9.8): Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated…
- CVE-2025-48481 — Critical (CVSS 9.8): FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, an attacker with an unactivated…
- CVE-2022-2105 — Critical (CVSS 9.4): Client-side JavaScript controls may be bypassed to change user credentials and permissions without authentication,…
- CVE-2026-34582 — Critical (CVSS 9.1): Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData…
- CVE-2026-95369 — High (CVSS 8.8): Inappropriate implementation in XML in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially…
- CVE-2025-48476 — High (CVSS 8.8): FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, when adding and editing user…