VDB
Sign up

EEF-CVE-2026-87119

mpp Tempo subscription key authorization is not bound to the issuing challenge, allowing a captured activation credential to be replayed

Quick fix

EEF-CVE-2026-87119 — mpp: upgrade to the fixed version with the command below.

mix deps.update mpp

Details

## Summary

Authentication Bypass by Capture-replay in ZenHive mpp allows an attacker holding a captured subscription activation credential to charge the payer repeatedly.

The payer signs a Tempo `KeyAuthorization` over the chain id, key type, key id, expiry, limits and scopes only, with nothing tying it to the challenge that prompted it. `MPP.Methods.Tempo.KeyAuthorization.verify/3` in `lib/mpp/methods/tempo/key_authorization.ex` pins each of those signed fields against the subscription request, and the access key it pins is a static per-endpoint server key, so one signed authorization verifies against every challenge the server issues for the same subscription terms. `MPP.Methods.Tempo.Subscription.activate/4` deduplicates activations by challenge id, so presenting the captured credential under a fresh challenge produces a different dedup key, `claim_activation` succeeds, and the subscription transaction is built and broadcast again. Each replay charges the payer's wallet a new first-period settlement and re-authorizes the server key, bounded only by the subscription expiry and the chain's own semantics for re-installing an existing key.

This issue affects mpp: from 0.14.0 before 0.16.2.

## Impact

An attacker who obtains a payer's subscription activation credential (from a non-TLS hop, a log, a compromised intermediary, or the client's own retry buffer) can present it under fresh challenges to settle repeated first-period charges against that payer's wallet and re-authorize the server's access key. The payer bears the on-chain cost, limited only by the per-period subscription limit and the subscription expiry.

## Configurations

Only deployments offering Tempo subscriptions are affected, which requires `subscription_access_key_private_key` in the Tempo `method_config`. Exploitation further requires the attacker to have obtained a payer's signed activation credential, in transit over a hop that is not TLS-protected or at rest in a log, an intermediary, or a client retry buffer.

Are you affected?

Enter the version of the package you're using.

Affected packages

Hex/mpp
Introduced in: 0.14.0Fixed in: 0.16.2
Fixmix deps.update mpp

References