Two high-severity flaws in anchor-lang weakened account validation in Solana programs, allowing attackers to substitute unexpected accounts and potentially bypass authorization or alter program behavior. CVE-2026-45137 affects versions 1.0.0 through before 1.0.2 and stems from Program<'info, System> being validated through generic Program<T> logic that treated the system program like an untyped program because both resolved to Pubkey::default(). As a result, applications expecting the real Solana system program could accept any executable program account instead, creating risk of arbitrary cross-program invocation, payment bypass, or incorrect assumptions around account creation and other system-program operations.
A separate InterfaceAccount bug, tracked as GHSA-429q-fhh4-r6hj, affected anchor-lang 1.0.0-rc.1 after a change disabled checked deserialization and left validation relying mainly on owner checks. That flaw allowed accounts with unexpected Anchor discriminators to be passed as valid interface accounts, enabling account-type substitution and possible state or authorization bypasses. OtterSec fixed the InterfaceAccount issue in pull request #4139 and released it in 1.0.0-rc.2, restoring checked deserialization while preserving an explicit unchecked path; the Program<System> validation flaw was fixed in 1.0.2 by separating typed and untyped program validation and enforcing a match to the real system program ID.

See affected versions and whether adversaries are exploiting it.
10 events from the most recent confirmed update back to the earliest known activity.
RustSec issued advisory RUSTSEC-2026-0146 for the high-severity InterfaceAccount validation vulnerability in anchor-lang. The advisory states it was issued on 2026-05-19.
RustSec issued advisory RUSTSEC-2026-0144 for the high-severity Program<System> validation vulnerability in anchor-lang. The advisory states it was issued on 2026-05-18.
OtterSec released anchor-lang 1.0.0-rc.2 containing the fix for the InterfaceAccount substitution issue, restoring checked deserialization for InterfaceAccount::try_from. The content confirms the fixed version but does not explicitly anchor the release date.
The InterfaceAccount account-substitution vulnerability in anchor-lang was reported to the project. The RustSec advisory explicitly gives the report date as 2026-05-08.
Anchor fixed the Program<System> validation flaw in version 1.0.2 by separating typed Program<T> validation from the untyped path and enforcing the real system program ID check. This remediation is described in the advisory, but no explicit release date is provided in the content.
The vulnerability later tracked as CVE-2026-45137 in anchor-lang's Program<System> validation was reported. The RustSec advisory states the report date was 2026-05-07.
The fix for unexpected account substitution in InterfaceAccount was merged into master, with code changes enforcing owner checks and checked deserialization while preserving a separate unchecked path. The merge and associated commit occurred on 2026-01-05.
Anchor pull request #4139 was published to remediate unexpected account substitution in InterfaceAccount by restoring stricter validation and adding security tests. The pull request publication date is 2025-12-19.
The Anchor pull request #3837 was merged into otter-sec:master after review and testing, cementing the change later linked to the InterfaceAccount vulnerability. The source states this merge occurred on 2025-11-19.
A change in Anchor pull request #3837 disabled discriminator checking in InterfaceAccount, creating the condition that later allowed unexpected account substitution between accepted interface-owned types. The pull request was published on 2025-08-12.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
7 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourcerustsec.org
Open sourcerustsec.org
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.