CVE-2026-105097
Received Received - Intake

Authorization Bypass in Omega Solution CoinEx Crypto 2025

Vulnerability report for CVE-2026-105097, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-04

Last updated on: 2026-10-04

Assigner: VulDB

Description

A vulnerability was identified in Omega Solution CoinEx Crypto 2025. This impacts an unknown function of the file /customer-currency/ of the component Customer Information API. The manipulation of the argument ID leads to authorization bypass. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The product web site does not exist anymore. Maybe the product got retired and/or replaced. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-04
Last Modified
2026-10-04
Generated
2026-10-04
AI Q&A
2026-10-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
omega coinex_crypto 2025

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-285 The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-105097 is a Broken Access Control vulnerability (Insecure Direct Object Reference - IDOR) in Omega Solution CoinEx Crypto 2025. It allows authenticated users to bypass authorization checks by manipulating the customer ID in the API endpoint /customer-currency/{id}. This enables attackers to access other users' sensitive data such as profiles, wallet balances, and password hashes by changing the ID parameter.

Detection Guidance

To detect this IDOR vulnerability, monitor API traffic for requests to /customer-currency/{id} where the ID parameter is manipulated. Use tools like Burp Suite or OWASP ZAP to intercept and modify GET requests, checking if unauthorized data is returned. Look for repeated successful responses with different IDs, indicating improper authorization checks.

Impact Analysis

This vulnerability allows attackers to access other users' personally identifiable information (PII), financial details, and cryptographic wallet addresses. Attackers can enumerate all customer accounts by iterating numeric IDs, collect sensitive data, and potentially modify accounts by combining this flaw with other IDOR vulnerabilities.

Compliance Impact

This vulnerability likely violates GDPR and HIPAA due to unauthorized access to PII and financial data. GDPR requires strict protection of personal data, while HIPAA mandates safeguards for protected health information. The exposure of password hashes and sensitive financial details further increases compliance risks.

Mitigation Strategies

Immediately enforce strict object-level authorization checks in the API. Validate that the requested customer ID matches the authenticated user's ID. Remove sensitive data like password hashes from API responses. Implement rate limiting to prevent ID enumeration. Update the application to return 403 Forbidden or 404 Not Found for unauthorized access attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105097. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart