XRPL Vulnerabilities: Permission Delegation and Batch Amendment Bugs
Article Content
- •The XRPL Permission Delegation bug could drain XRP by charging unauthorized fees.
- •The Batch amendment bug allowed unauthorized fund transfers without private keys.
- •Both vulnerabilities were identified before activation on the mainnet, preventing potential exploitation.
Two critical vulnerabilities were reported in the XRPL system affecting different amendments. The first, identified on September 15, 2025, involved the Permission Delegation feature, allowing unauthorized transaction fees to drain XRP from victim accounts. This bug was discovered during the voting phase and was not active on the mainnet. The second bug, reported on February 19, 2026, in the Batch amendment, allowed attackers to execute transactions on behalf of victim accounts without their private keys due to a logic flaw. Both vulnerabilities prompted immediate actions from UNL validators to vote against the amendments, preventing their activation on the mainnet. Remediation efforts are underway, with revised amendments planned for future releases. No funds were at risk for the Batch amendment as it was also in the voting phase when the bug was discovered.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Cantina AI in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…