


Perceptive Security
SOC/SIEM Consultancy

Anchor is a framework providing several convenient developer tools for writing Solana programs. From 1.0.0 to before 1.0.2, an logic error causes anchor program…
Published:
26 mei 2026 om 22:00:00
Alert date:
27 mei 2026 om 22:02:45
Source:
nvd.nist.gov
Web Technologies, Supply Chain & Dependencies
CVE-2026-45137 affects the Anchor framework for Solana programs from versions 1.0.0 to before 1.0.2. A logic error causes anchor programs to accept any program ID when requiring the system program ID, leading to false assumptions. This vulnerability can result in arbitrary CPI (Cross-Program Invocation) or payment bypassing when programs make CPI calls to the system program. The issue stems from improper validation in the TryFrom implementation for Program<'a, T>, where attackers can pass any executable program instead of the legitimate system program. The vulnerability is fixed in version 1.0.2.
Technical details
Mitigation steps:
Affected products:
Anchor Framework
Solana
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-45137
https://github.com/otter-sec/anchor/security/advisories/GHSA-c6rc-8jpp-2fgc
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
