Vulnary
← back to the feed
Critical· 9.3official fix available

CVE-2026-54496

A flaw in the ZEBRA Zcash node's variable-base scalar multiplication gadget allowed attackers to create valid proofs with an under-constrained base point, bypassing integrity checks for diversified addresses. The issue affected versions before zebrad 5.0.0, halo2_gadgets 0.5.0, orchard 0.14.0, zcash_primitives 0.28.0, and zcashd 6.20.0. Updating to those versions resolves the vulnerability.

publishedJul 17, 2026
last modifiedJul 17, 2026
sourcesNVD
severity · cvss
9.3
critical · how bad it is
exploitation · epss
<1%
11th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Sep 1, 2026

No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.

01

Who is affected

Users of ZEBRA/Zcash components prior to the fixed versions.

02

Real-world impact

An attacker could forge proofs that bypass diversified-address integrity checks, potentially allowing unauthorized spends.

03

Why this severity

CVSS v3.1 base score 9.3 (Critical) due to network attack vector, low complexity, no privileges or user interaction required, with high integrity impact and low availability impact.

04

What to do about it

official fix available
recommended steps
  1. 01Upgrade zebrad to version 5.0.0 or later.
  2. 02Upgrade halo2_gadgets to version 0.5.0 or later.
  3. 03Upgrade orchard to version 0.14.0 or later.
  4. 04Upgrade zcash_primitives to version 0.28.0 or later.
  5. 05Upgrade zcashd to version 6.20.0 or later.

Fix information comes directly from the NVD description.

05

Timeline

06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionNone needed
ScopeChanged
Confidentiality impactNone
Integrity impactHigh
Availability impactLow
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →