Sceawere

Vulnerability Detail

CVE-2026-105444UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Insecure Direct Object Reference in eShop

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.3
Creation Date
2h ago
Vendor
dotnet
Product
eShop
Attack Type
Improper Control of Resource Identifiers
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A security flaw has been discovered in dotnet eShop .NET 8. The impacted element is the function GetOrderAsync of the file src/Ordering.API/Apis/OrdersApi.cs of the component Ordering API. Performing a manipulation of the argument OrderNumber results in improper control of resource identifiers. The attack is possible to be carried out remotely. The project was informed of the problem early through an issue report but has not responded yet.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.3",
  "pubDate": "2026-10-05T21:16:34.470Z",
  "pubdate": "2026-10-05T21:16:34.470Z",
  "executiveSummary": "A vulnerability classified as improper control of resource identifiers has been identified in the dotnet eShop .NET 8 Ordering API.\nThe flaw resides within the GetOrderAsync function in src/Ordering.API/Apis/OrdersApi.cs and permits unauthorized access to order data.\nThis vulnerability constitutes an Insecure Direct Object Reference (IDOR) issue, enabling remote attackers to retrieve information regarding arbitrary orders by manipulating the OrderNumber argument.\nThe risk implication is significant as it facilitates unauthorized data exposure, potentially leading to a breach of sensitive customer information and transactional integrity.\nExploitation requires no elevated privileges and can be executed remotely via standard API interaction, posing a severe threat to data confidentiality.\nThe project maintainers have been notified of this security flaw, yet no official patch or remedial response has been issued to date.",
  "technicalDetails": "The vulnerability is situated within the GetOrderAsync function located in src/Ordering.API/Apis/OrdersApi.cs, a critical component of the Ordering API in dotnet eShop .NET 8.\nThe root cause is an improper implementation of access control checks regarding user-supplied resource identifiers. The application accepts an OrderNumber as an input argument without validating whether the authenticated user possesses the authorization to access the specific order entity associated with that identifier.\nThe attack vector involves a remote, unauthenticated or low-privilege actor manipulating the OrderNumber parameter during the API request. By iterating through or guessing valid identifier sequences, an attacker can bypass the intended authorization logic to retrieve order details belonging to other users.\nStep-by-step attack flow: 1. The attacker intercepts a legitimate request to the Ordering API that utilizes the GetOrderAsync function. 2. The attacker modifies the OrderNumber parameter in the API request body or URL path. 3. The server-side logic fails to verify the ownership of the requested OrderNumber against the current user context. 4. The function proceeds to execute the database query using the attacker-supplied, unauthorized identifier. 5. The application returns the sensitive order data corresponding to the manipulated OrderNumber to the attacker, resulting in unauthorized data exposure.\nThe vulnerability is primarily an IDOR flaw that exploits a lack of server-side authorization checks for object-level access. Because the code fails to map the requested order resource to the authenticated session's identity, the system essentially provides unrestricted access to any resource identifier provided by the user.\nPost-exploitation, an attacker can perform mass enumeration of order records, leading to a complete compromise of customer data confidentiality, potentially exposing PII (Personally Identifiable Information), historical transaction logs, and internal supply chain metrics stored within the Ordering API."
}
CVE-2026-105444: Insecure Direct Object Reference in eShop (MEDIUM Severity, CVSS: 6.3) | Sceawere