CVE-2026-4931 is a medium-severity vulnerability affecting the Marginal v1 smart contract that exploits an unsafe downcast flaw in its code. This vulnerability allows attackers to manipulate the contract's settlement mechanism by settling disproportionately large debt positions while paying only negligible asset costs, creating a significant financial exploitation vector. The vulnerability carries a CVSS score of 6.8 (Medium) and can be exploited over the network without authentication or user interaction, though it requires high technical complexity to execute. The primary impact is integrity compromise of the smart contract's financial mechanisms, with no direct confidentiality or availability consequences expected. Currently, CVE-2026-4931 is not listed on the Known Exploited Vulnerabilities catalog and shows no evidence of active exploitation in the wild. The EPSS score of 0.000410000 indicates minimal probability of exploitation, and community attention to this vulnerability remains low relative to other disclosed CVEs. Organizations using Marginal v1 should monitor for patches but face limited immediate risk based on current threat data.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.0.2CPE matchmatch criteria | cpe:2.3:a:marginal:v1-core:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.