
CBDC Infrastructure Vulnerability Research. CVE-2026-78904: Infinite mint and redemption bypass in central bank digital currency APIs.
| Field | Value |
|---|
| Severity | 9.8 (Critical) |
| Vector | Network |
| Affected Versions | 2.1.0 – 2.1.3 |
| Discovered By | 𝕍𝕠𝕤𝕤🥷 |
A critical logic flaw in the CBDC issuance API allows an attacker with low‑level access to manipulate the minting and redemption endpoints. This enables the creation or destruction of CBDC units without authorisation.