rootpwn

medium · CVSS v3 6.3 · CVSS v4 5.3 · EPSS 0.00285

CVE-2026-105096

CVE-2026-105096 is an authorization bypass vulnerability in the Customer Profile API of Omega Solution CoinEx Crypto 2025. By manipulating t

Overview

CVE-2026-105096 is an authorization bypass vulnerability in the Customer Profile API of Omega Solution CoinEx Crypto 2025. By manipulating the ID parameter in the /customer/ endpoint, an attacker can gain unauthorized access to customer data. The flaw is exploitable remotely and has been publicly disclosed.

Description

A vulnerability was determined in Omega Solution CoinEx Crypto 2025. This affects an unknown function of the file /customer/ of the component Customer Profile API. Executing a manipulation of the argument ID can lead to authorization bypass. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The product web site does not exist anymore. Maybe the product got retired and/or replaced. The vendor was contacted early about this disclosure but did not respond in any way.

Impact

The vulnerability allows attackers to bypass authorization controls, potentially accessing or modifying customer profiles. This compromises confidentiality, integrity, and availability of sensitive user data. Defenders should treat affected systems as high risk for data exposure.

Remediation

Apply the vendor’s security patch if available. If no patch exists, disable or restrict the /customer/ API endpoint, enforce strict input validation on the ID parameter, and implement role‑based access controls. Monitor logs for anomalous ID usage and block suspicious traffic.

Risk context

Medium severity (CVSS 6.3) with a low EPSS score of 0.00285 indicates a moderate but not imminent threat. However, the public disclosure and remote exploitation potential warrant timely mitigation.

Affected products

  • Omega Solution CoinEx Crypto 2025

Scores

Severity
medium
CVSS v2
6.5
CVSS v3
6.3
CVSS v4
5.3
EPSS
0.00285

authorization-bypass remote-exploit API customer-profile medium-severity EPSS-low

← All CVEs