Sceawere
Vulnerability Detail
CVE-2026-19208UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
WonderTrader TraderDD Workflow Enforcement Vulnerability
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 3.7
- Creation Date
- 21h ago
- Vendor
- n/a
- Product
- WonderTrader
- Attack Type
- Enforcement of Behavioral Workflow
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
A vulnerability was detected in WonderTrader up to 0.9.9. Impacted is the function TraderDD::queryTrades of the file src/TraderDD/TraderDD.cpp. The manipulation of the argument FID_JYLB results in enforcement of behavioral workflow. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "3.7",
"pubDate": "2026-08-07T16:17:23.750Z",
"pubdate": "2026-08-07T16:17:23.750Z",
"executiveSummary": "A vulnerability has been identified in WonderTrader up to version 0.9.9, specifically within the TraderDD::queryTrades function located in the src/TraderDD/TraderDD.cpp file.\nThe vulnerability involves the manipulation of the argument FID_JYLB, which results in the enforcement of behavioral workflows within the trading system.\nThis security flaw can be exploited remotely by an attacker, leading to unauthorized manipulation of application execution flow and workflow enforcement.\nThe attack is characterized by a high complexity level, and the overall exploitability is considered difficult, requiring precise conditions to successfully alter system behavior.\nDespite the high complexity, public exploits are currently available, posing a direct threat to deployments utilizing unpatched versions of the software.\nThe vendor was contacted prior to public disclosure but failed to respond or provide an official remediation path.\nOrganizations running affected instances face potential integrity risks regarding their trade query execution and behavioral workflow logic.\nMitigation remains challenging due to the lack of an official vendor patch, necessitating compensating controls at the network and application layers.",
"technicalDetails": "The vulnerability resides in the WonderTrader codebase, specifically inside the TraderDD::queryTrades function implemented in src/TraderDD/TraderDD.cpp.\nThe root cause stems from insufficient validation, sanitization, and handling of input parameters passed to the application, specifically the argument designated as FID_JYLB.\nBy manipulating the FID_JYLB parameter, an external threat actor can influence conditional execution paths and state transitions, resulting in the enforcement of unintended behavioral workflows.\nThe attack vector is remote, indicating that network exposure is present, allowing interaction with the vulnerable endpoint or function without requiring prior physical access.\nExploitation is classified as having a high complexity level and is difficult to execute, suggesting that attackers must overcome strict structural or environmental constraints to successfully trigger the flaw.\nThe step-by-step attack flow begins with the attacker crafting a malicious payload containing modified or unexpected values for the FID_JYLB argument.\nThis payload is transmitted remotely to the target instance of WonderTrader, which routes the input to the TraderDD::queryTrades function.\nUpon processing the input within src/TraderDD/TraderDD.cpp, the application fails to adequately validate the boundaries or expected states of FID_JYLB.\nConsequently, the internal logic evaluates the manipulated argument and enforces a modified behavioral workflow that deviates from expected operational constraints.\nThis unauthorized workflow enforcement can disrupt standard processing logic, alter transaction query behaviors, or force the application into unintended execution states.\nAffected software versions include all iterations of WonderTrader up to and including version 0.9.9.\nPost-exploitation impact includes the potential subversion of trading query logic, logical tampering, and disruption of system integrity.\nNo explicit authentication or privilege requirements are detailed beyond the ability to reach the vulnerable remote interface, though the high complexity and difficulty imply that successful exploitation requires detailed knowledge of the target's internal workflow structures."
}