CVE-2020-26895

MEDIUM

LND <0.10.0-beta - Privilege Escalation

Title source: llm
STIX 2.1

Description

Prior to 0.10.0-beta, LND (Lightning Network Daemon) would have accepted a counterparty high-S signature and broadcast tx-relay invalid local commitment/HTLC transactions. This can be exploited by any peer with an open channel regardless of the victim situation (e.g., routing node, payment-receiver, or payment-sender). The impact is a loss of funds in certain situations.

Scores

CVSS v3 5.3
EPSS 0.0015
EPSS Percentile 34.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-354
Status published
Products (22)
lightning_network_daemon_project/lightning_network_daemon 0.1 alpha
lightning_network_daemon_project/lightning_network_daemon 0.1.1 alpha
lightning_network_daemon_project/lightning_network_daemon 0.2 alpha
lightning_network_daemon_project/lightning_network_daemon 0.2.1 alpha
lightning_network_daemon_project/lightning_network_daemon 0.3 alpha
lightning_network_daemon_project/lightning_network_daemon 0.4 beta
lightning_network_daemon_project/lightning_network_daemon 0.4.1 beta
lightning_network_daemon_project/lightning_network_daemon 0.4.2 beta
lightning_network_daemon_project/lightning_network_daemon 0.5 beta (3 CPE variants)
lightning_network_daemon_project/lightning_network_daemon 0.5.1 beta (5 CPE variants)
... and 12 more
Published Oct 21, 2020
Tracked Since Feb 18, 2026