Sceawere
Vulnerability Detail
CVE-2026-105097UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Omega Solution CoinEx Authorization Bypass
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 4h ago
- Vendor
- Omega Solution
- Product
- CoinEx Crypto
- Attack Type
- Authorization Bypass
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was identified in Omega Solution CoinEx Crypto 2025. This impacts an unknown function of the file /customer-currency/ of the component Customer Information API. The manipulation of the argument ID leads to authorization bypass. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The product web site does not exist anymore. Maybe the product got retired and/or replaced. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-10-04T03:16:49.460Z",
"pubdate": "2026-10-04T03:16:49.460Z",
"executiveSummary": "A critical authorization bypass vulnerability has been identified in the Omega Solution CoinEx Crypto 2025 platform, specifically within the Customer Information API component.\nThe vulnerability originates from improper access control validation when processing the 'ID' argument within the '/customer-currency/' file path.\nSuccessful exploitation allows remote, unauthenticated attackers to bypass authorization checks, potentially gaining unauthorized access to sensitive customer currency and information data structures.\nThe risk is exacerbated by the availability of public exploit code and the vendor's failure to respond to initial disclosure efforts.\nGiven that the product's official web presence is defunct, indicating potential retirement, organizations still hosting instances of this software are at significant risk of persistent, unpatched exploitation.\nAttackers do not require local access, as the vulnerability is remotely exploitable over the network, permitting data exfiltration without valid credentials.",
"technicalDetails": "The vulnerability resides in the Customer Information API component, specifically manifesting within the '/customer-currency/' endpoint. The root cause is identified as an Improper Authorization flaw, where the application fails to adequately verify the requester's identity or permission level before granting access to sensitive data associated with a provided 'ID' parameter.\nUnder normal operating conditions, the '/customer-currency/' endpoint is intended to serve customer-specific financial data based on a validated session. However, the input validation logic for the 'ID' argument is flawed. The backend service accepts arbitrary values for the 'ID' parameter without enforcing strict server-side authorization checks to ensure the requesting user is the rightful owner of the data associated with that specific ID.\nThe attack flow proceeds as follows: 1) An attacker identifies the target endpoint '/customer-currency/'. 2) The attacker crafts a request containing an manipulated 'ID' parameter. 3) Because the server-side API logic does not validate the relationship between the authenticated session (or lack thereof) and the requested 'ID', the server processes the request as a legitimate query. 4) The application then returns the sensitive financial or currency information associated with the target 'ID' to the attacker, effectively bypassing all intended authorization boundaries.\nBecause the exploit is publicly available, the attack surface is significantly expanded. An attacker can use automated tools to iterate through ID sequences, leading to large-scale data harvesting or mass unauthorized access to customer records. The lack of secondary validation or restrictive access control lists (ACLs) within the component makes the application susceptible to unauthorized information disclosure, potentially leading to a complete compromise of the confidentiality of the customer currency management system.\nSince the product is no longer maintained by the vendor, there is no hope for an official patch, meaning any instance of this software remains inherently insecure against this bypass vector. Furthermore, since the API does not enforce granular session-to-resource mapping, the vulnerability remains trivial to trigger for anyone with network connectivity to the API service."
}