HackerOne Disclosed Reports - 2026-08-17

0 Replies, 5 Views

Logo
High
resolved

Wallet RPC Restricted-Mode Policy Bypass


Bug reported by usagirabbit was disclosed at August 17, 2026, 9:16 am   |   Improper Authentication - Generic

A vulnerability was discovered in the Monero wallet RPC server that allowed restricted-mode clients to perform non-view-only operations. The issue was caused by inconsistent enforcement of the restricted mode, which allowed clients to bypass the intended view-only access controls and perform state-changing actions such as creating wallets, closing wallets, and mutating wallet state. The vulnerability was confirmed to be present in multiple versions of the Monero software.


Logo
High
resolved

Restricted RPC Policy Bypass on ZMQ JSON-RPC Allows Unauthenticated Remote Admin Actions


Bug reported by usagirabbit was disclosed at August 17, 2026, 9:16 am   |   Improper Authentication - Generic

A high-severity access-control issue was found in Monero's ZMQ JSON-RPC surface. When the daemon is started in restricted/public-node mode, the HTTP RPC layer correctly suppresses admin-only methods, but the ZMQ JSON-RPC layer did not inherit or enforce that restriction. This allowed an unauthenticated remote client to invoke state-changing methods that should have been unavailable in restricted mode.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]



Users browsing this thread: 1 Guest(s)