DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-82405: CVE-2026-82405: Incorrect Authorization leading to Account Takeover in klever-go

CVE-2026-82405: Incorrect Authorization leading to Account Takeover in klever-go

Vulnerability ID: CVE-2026-82405
CVSS Score: 8.7
Published: 2026-09-23

A critical incorrect authorization vulnerability (CWE-863) exists in the Go implementation of the Klever blockchain protocol (klever-go) prior to version 1.7.20. The vulnerability allows an attacker to completely replace a target account's permission set by manipulating the RecipientAddr parameter in a VM built-in function, leading to total account takeover.

TL;DR

An incorrect authorization flaw in klever-go < 1.7.20 allows attackers to overwrite any account's permission set using a malicious contract call, resulting in unauthorized account takeover.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-863
  • Attack Vector: Network
  • CVSS v4.0 Score: 8.7 (High)
  • Exploit Status: PoC Available
  • CISA KEV Status: Not Listed
  • Remediation Status: Patched in v1.7.20

Affected Systems

  • klever-go
  • klever-go: < 1.7.20 (Fixed in: 1.7.20)

Code Analysis

Commit: c58740e

Fix validation bypass vulnerability in UpdateAccountPermission built-in

Exploit Details

  • GitHub: Functional Unit Test Proof of Concept demonstrating account takeover

Mitigation Strategies

  • Upgrade all running node implementations of klever-go to version 1.7.20 or later.
  • Verify that all custom blockchain integrations pass cryptographically validated caller addresses to permission endpoints.
  • Monitor on-chain events for unexpected UpdatePermission contract executions.

Remediation Steps:

  1. Download the patched release of klever-go (version 1.7.20) from the official GitHub repository.
  2. Compile the node binary using Go and deploy it to validator and public node hosts.
  3. Verify the version output of the running daemon to confirm the patch is active.
  4. Conduct a state-level audit of registered permissions to identify any unauthorized self-signing modification events.

References


Read the full report for CVE-2026-82405 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)