Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-78904-Digital-Dinar-Drain — CBDC Infrastructure Vulnerability Research. CVE-2026-78904: Infinite mint and redemption bypass in central bank digital currency APIs. | Kitploit
Tools/GitHubGitHub/vxssroott/cve-2026-78904-digital-dinar-drain
Vulnerability AnalysisExploitationWeb Application ExploitationAPI Security
GitHubvxssroott/cve-2026-78904-digital-dinar-drain

CVE-2026-78904-Digital-Dinar-Drain

CBDC Infrastructure Vulnerability Research. CVE-2026-78904: Infinite mint and redemption bypass in central bank digital currency APIs.

View Repository
41020 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-78904 — Digital Dinar Drain

CBDC Issuance API — Logic Flaw (Infinite Mint)

FieldValue
Severity9.8 (Critical)
VectorNetwork
Affected Versions2.1.0 – 2.1.3
Discovered By𝕍𝕠𝕤𝕤🥷

Description

A critical logic flaw in the CBDC issuance API allows an attacker with low‑level access to manipulate the minting and redemption endpoints. This enables the creation or destruction of CBDC units without authorisation.

Impact

  • Unauthorised minting of CBDC units
  • Manipulation of redemption requests
  • Infinite mint attack vector

Mitigation

  • Upgrade to CBDC Issuance API 2.1.4 or later
  • Implement rate‑limiting on mint/redemption endpoints
  • Enforce multi‑factor authorisation for all administrative actions

Timeline

  • 2026-08-30: Vulnerability discovered
  • 2026-08-31: Public disclosure
Download Tool