CVE-2026-82405: Incorrect Authorization leading to Account Takeover in klever-go
Vulnerability ID: CVE-2026-82405
CVSS Score: 8.7
Published: 2026-09-23
A critical incorrect authorization vulnerability (CWE-863) exists in the Go implementation of the Klever blockchain protocol (klever-go) prior to version 1.7.20. The vulnerability allows an attacker to completely replace a target account's permission set by manipulating the RecipientAddr parameter in a VM built-in function, leading to total account takeover.
TL;DR
An incorrect authorization flaw in klever-go < 1.7.20 allows attackers to overwrite any account's permission set using a malicious contract call, resulting in unauthorized account takeover.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-863
- Attack Vector: Network
- CVSS v4.0 Score: 8.7 (High)
- Exploit Status: PoC Available
- CISA KEV Status: Not Listed
- Remediation Status: Patched in v1.7.20
Affected Systems
- klever-go
-
klever-go: < 1.7.20 (Fixed in:
1.7.20)
Code Analysis
Commit: c58740e
Fix validation bypass vulnerability in UpdateAccountPermission built-in
Exploit Details
- GitHub: Functional Unit Test Proof of Concept demonstrating account takeover
Mitigation Strategies
- Upgrade all running node implementations of klever-go to version 1.7.20 or later.
- Verify that all custom blockchain integrations pass cryptographically validated caller addresses to permission endpoints.
- Monitor on-chain events for unexpected UpdatePermission contract executions.
Remediation Steps:
- Download the patched release of klever-go (version 1.7.20) from the official GitHub repository.
- Compile the node binary using Go and deploy it to validator and public node hosts.
- Verify the version output of the running daemon to confirm the patch is active.
- Conduct a state-level audit of registered permissions to identify any unauthorized self-signing modification events.
References
- GHSA-97cv-x867-6xhm Security Advisory
- Fix Commit on GitHub
- Technical Proof of Concept
- Klever Go v1.7.20 Release Tag
Read the full report for CVE-2026-82405 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)