Sceawere

Vulnerability Detail

CVE-2026-19213UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

WonderTrader Pending Order Behavioral Enforcement

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
19h ago
Vendor
n/a
Product
WonderTrader
Attack Type
Enforcement of Behavioral Workflow
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was identified in WonderTrader up to 0.9.9. Affected is the function _undone_qty in the library src/WtCore/TraderAdapter.h of the component Pending Order Handler. The manipulation of the argument getUndoneQty leads to enforcement of behavioral workflow. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-08-07T18:17:12.793Z",
  "pubdate": "2026-08-07T18:17:12.793Z",
  "executiveSummary": "A vulnerability has been identified in WonderTrader up to version 0.9.9, specifically within the Pending Order Handler component. The flaw resides in the function _undone_qty located in the library src/WtCore/TraderAdapter.h. Manipulation of the getUndoneQty argument leads to the enforcement of behavioral workflows, allowing an unauthorized state modification or logic bypass within the trading engine. This vulnerability can be exploited remotely by malicious actors, and public exploits are currently available, increasing the risk of active exploitation. The vendor was contacted early regarding this security issue but failed to provide any response or official patch. Consequently, systems running affected versions of WonderTrader are exposed to potential remote exploitation, risking unintended trade executions, order management bypasses, and overall financial workflow integrity compromise. Immediate risk mitigation is strongly advised despite the lack of a vendor-supplied patch.",
  "technicalDetails": "The vulnerability stems from insufficient input validation and insecure state handling within the Pending Order Handler of WonderTrader up to version 0.9.9. The core issue is located in the function _undone_qty within the source file src/WtCore/TraderAdapter.h. Specifically, the processing and manipulation of the getUndoneQty argument fail to adequately verify the integrity and provenance of the data being supplied. This permits remote attackers to influence the control flow and enforce specific behavioral workflows related to pending order quantities.\nFrom an architectural standpoint, TraderAdapter.h serves as an interface layer bridging core trading logic with external adapter communications. By leveraging the exposed remote attack surface, an adversary can craft malicious input targeting the getUndoneQty parameter. When the _undone_qty function processes this manipulated argument, it miscalculates or incorrectly enforces pending order states, leading to unauthorized state transitions or logic enforcement bypasses.\nThe attack flow begins with the remote adversary identifying the exposed network service handling trader adapter communications in WonderTrader. The attacker then constructs a specially crafted payload targeting the Pending Order Handler mechanism. By injecting this payload into the getUndoneQty interface parameter, the attacker forces the _undone_qty function to evaluate incorrect quantity metrics. This manipulation causes the internal trading engine to misinterpret pending order states, thereby enforcing unintended behavioral workflows. The exploitation does not require prior authentication or elevated privileges if the underlying service is exposed to untrusted networks. The post-exploitation impact includes the potential distortion of order execution logic, artificial manipulation of pending quantities, and disruption of automated trading strategies relying on accurate state reporting within WonderTrader."
}
CVE-2026-19213: WonderTrader Pending Order Behavioral Enforcement (MEDIUM Severity, CVSS: 4.3) - Sceawere