CVE-2026-86840
NONE—CVSS v3
—CVSS v2
—
EPSS (exploit probability)
—CWE
Description
The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission attribution. A signed account can supply an arbitrary registered `channel_id` when minting tokens without verifying that the caller is authorized to mint on behalf of that channel. This allows an attacker to inflate a channel's recorded mint volume and cause protocol commission payments to be disproportionately distributed to that channel during commission settlement.
Affected routers (0)
No routers currently mapped to this CVE in our database.