Sceawere

Vulnerability Detail

CVE-2026-105098UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Information Disclosure in Omega Solution

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
3h ago
Vendor
Omega Solution
Product
CoinEx Crypto
Attack Type
Information Disclosure
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

A security flaw has been discovered in Omega Solution CoinEx Crypto 2025. Affected is an unknown function of the file /ticket/customer of the component Support Ticket API. The manipulation of the argument status/page/count results in information disclosure. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The product web site does not exist anymore. Maybe the product got retired and/or replaced. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-10-04T04:16:36.140Z",
  "pubdate": "2026-10-04T04:16:36.140Z",
  "executiveSummary": "A critical information disclosure vulnerability has been identified within the Omega Solution CoinEx Crypto 2025 platform. The flaw originates from improper input validation within the Support Ticket API, specifically affecting the /ticket/customer endpoint.\nThis vulnerability allows an unauthenticated, remote attacker to manipulate specific API query parameters—namely 'status', 'page', and 'count'—to bypass authorization controls and retrieve sensitive information that should otherwise be restricted.\nThe risk is exacerbated by the fact that the vendor is unresponsive and the product is no longer maintained or supported, leaving no path for official vendor-supplied patches.\nThe existence of public exploit code increases the likelihood of successful exploitation by malicious actors targeting the remaining legacy installations of this software.\nOrganizations still utilizing this software are at significant risk of data breaches, specifically concerning customer-related support ticket metadata or potentially sensitive user information stored within the affected component.",
  "technicalDetails": "The vulnerability resides within the Support Ticket API of the Omega Solution CoinEx Crypto 2025 platform, specifically manifesting in an undocumented or obscure function associated with the /ticket/customer file path.\nThe root cause is an insecure implementation of server-side data filtering and access control logic. The application fails to properly validate the 'status', 'page', and 'count' parameters before processing database queries or object retrieval requests within the API.\nExploitation is achieved through remote HTTP requests directed at the /ticket/customer endpoint. An attacker can perform parameter tampering by supplying crafted input values to the identified arguments. By manipulating the 'status' parameter, the attacker may force the application to return ticket records with varying visibility levels. Simultaneously, by altering the 'page' and 'count' parameters, the attacker can conduct automated reconnaissance or 'scraping' of the ticket database, systematically extracting data in bulk.\nThe attack flow follows a predictable pattern: 1) The attacker targets the /ticket/customer endpoint via an external network request. 2) The attacker crafts an HTTP GET or POST request containing modified 'status', 'page', and 'count' values designed to bypass standard result-set limitations. 3) The backend API, lacking sufficient authorization logic for these specific input parameters, executes a query that aggregates sensitive information. 4) The server returns a structured response (likely JSON) containing the unauthorized data to the attacker.\nBecause the component handles support tickets, the disclosure impact likely includes the unauthorized access to sensitive customer identifiers, issue descriptions, internal support notes, and potentially PII (Personally Identifiable Information) associated with the ticket ecosystem.\nThe vulnerability requires no prior authentication, as the affected API endpoint does not enforce session validation or proper privilege escalation checks for the manipulated parameters. The network exposure is total, as the API remains accessible via standard web protocols. Post-exploitation, an attacker can maintain a persistent stream of information leakage by iterating through pagination values, effectively dumping the entire accessible ticket repository."
}
CVE-2026-105098: Information Disclosure in Omega Solution (MEDIUM Severity, CVSS: 4.3) | Sceawere