Critical
CVE-2026-87119
NVD
23 Sep 2026
Authentication Bypass in ZenHive mpp Allows Credential Replay Attack
A flaw in ZenHive mpp permits an attacker to charge a payer repeatedly by capturing and replaying a subscription activation credential. This bypasses proper authorization checks tied to the initial signing process. Affected services must enforce single-use tokens and validate all key authorization parameters upon transaction completion.