Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-4931

29
FAUCET Score

CVE-2026-4931 is a medium-severity vulnerability affecting the Marginal v1 smart contract that exploits an unsafe downcast flaw in its code. This vulnerability allows attackers to manipulate the contract's settlement mechanism by settling disproportionately large debt positions while paying only negligible asset costs, creating a significant financial exploitation vector. The vulnerability carries a CVSS score of 6.8 (Medium) and can be exploited over the network without authentication or user interaction, though it requires high technical complexity to execute. The primary impact is integrity compromise of the smart contract's financial mechanisms, with no direct confidentiality or availability consequences expected. Currently, CVE-2026-4931 is not listed on the Known Exploited Vulnerabilities catalog and shows no evidence of active exploitation in the wild. The EPSS score of 0.000410000 indicates minimal probability of exploitation, and community attention to this vulnerability remains low relative to other disclosed CVEs. Organizations using Marginal v1 should monitor for patches but face limited immediate risk based on current threat data.

Impacted Technologies

VendorProductVersion(s)CPE
<= 1.0.2CPE matchmatch criteria
cpe:2.3:a:marginal:v1-core:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.6HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
4.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.26%
Probability of exploitation in next 30 days
EPSS Percentile
17.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0026 is in the 3rd percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

cvefeed.io / cwe/detail/cwe-681-incorrect-conversion-between-numeric-types
Not Applicable
github.com / MarginalProtocol
Product
marginal.gitbook.io / docs
Product
medium.com / @clarkcorrin/cve-2026-4931-how-spearbits-cantina-denied-a-critical-vulnerability-using-verifiably-false-0a27b92ac2db
MitigationPress/Media CoverageThird Party Advisory
scs.owasp.org / SCWE/SCSVS-CODE/SCWE-041
Not Applicable