Sceawere

Vulnerability Detail

CVE-2026-105096UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Omega Solution CoinEx Authorization Bypass

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.3
Creation Date
3h ago
Vendor
Omega Solution
Product
CoinEx Crypto
Attack Type
Authorization Bypass
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was determined in Omega Solution CoinEx Crypto 2025. This affects an unknown function of the file /customer/ of the component Customer Profile API. Executing a manipulation of the argument ID can lead to authorization bypass. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The product web site does not exist anymore. Maybe the product got retired and/or replaced. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.3",
  "pubDate": "2026-10-04T02:16:28.740Z",
  "pubdate": "2026-10-04T02:16:28.740Z",
  "executiveSummary": "A critical authorization bypass vulnerability has been identified in the Customer Profile API of Omega Solution CoinEx Crypto 2025.\nThe vulnerability originates from improper handling of the ID argument within the /customer/ file, allowing unauthorized actors to circumvent access control mechanisms.\nThis flaw enables remote attackers to manipulate request parameters to gain unauthorized access to customer profile data without valid credentials.\nThe risk is exacerbated by the lack of vendor responsiveness and the fact that the product is no longer maintained or publicly accessible, increasing the likelihood of successful exploitation against legacy installations.\nExploitation does not require prior authentication, and the vulnerability can be leveraged via remote network requests to access sensitive user information.\nOrganizations still utilizing this software are at high risk of data exposure and potential account compromise.",
  "technicalDetails": "The vulnerability resides within the Customer Profile API, specifically interacting with the /customer/ file path. The root cause of the flaw is an inadequate validation and authorization check mechanism performed on the ID argument during API request processing.\nUnder normal operating conditions, the system is expected to perform a server-side verification of the requester's identity against the requested resource ID. However, the implementation fails to enforce these checks when an attacker supplies a manipulated ID parameter.\nThe attack flow begins with the adversary targeting the Customer Profile API remotely. By crafting a specific HTTP request targeting the /customer/ endpoint and injecting a modified, arbitrary, or predictive identifier into the ID argument, the attacker forces the application to return resource data associated with that identifier, bypassing the intended authorization layer.\nBecause the application logic does not sufficiently validate the session context or ownership rights of the user associated with the provided ID, the backend system processes the request as a legitimate retrieval operation.\nThe component fails to implement robust input sanitization and secure access control, effectively treating the user-supplied input as a trusted value for database queries or internal lookups. This allows an unauthorized user to perform horizontal or vertical privilege escalation, as they can enumerate or access sensitive profile information belonging to other users.\nThe vulnerability is exposed over the network, allowing for unauthenticated remote exploitation. Since the vendor has ceased operations and no official patches are available, the flaw remains permanently unmitigated in existing deployments. Post-exploitation impact includes full exposure of customer profile data, which may include personally identifiable information (PII) or other sensitive account details depending on the data structure handled by the /customer/ component. Attackers may utilize this publicly disclosed vulnerability to perform automated scraping or data harvesting on legacy systems."
}
CVE-2026-105096: Omega Solution CoinEx Authorization Bypass (MEDIUM Severity, CVSS: 6.3) | Sceawere