CVE-2026-48486 affects Signum Node, a Proof-of-Commitment HDD-mined cryptocurrency platform. Prior to version 3.9.9, an integer overflow vulnerability existed in the BlockServiceImpl.applyBlock() method. A malicious miner could exploit this by crafting a block with a negative totalFeeCashBackNqt value, resulting in an arbitrarily inflated block reward. The vulnerability was introduced with the SMART_FEES hardfork around block 1,029,000, which enabled fee cash-back and burn accounting without adequate overflow protection. This type of exploit could allow a bad actor to mint excessive cryptocurrency, undermining the economic integrity of the Signum network. The issue has been fully patched in Signum Node version 3.9.9. Users and node operators are strongly advised to upgrade immediately to mitigate potential exploitation.