CVE-2026-105097: medium-severity vulnerability in Omega Solution CoinEx Crypto
Omega Solution CoinEx Crypto Customer Information API customer-currency authorization
Published · Updated
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 5.3epss 0.3%
exploitation probability
0.3%top 80% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
A vulnerability was identified in Omega Solution CoinEx Crypto 2025. This impacts an unknown function of the file /customer-currency/ of the component Customer Information API. The manipulation of the argument ID leads to authorization bypass. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The product web site does not exist anymore. Maybe the product got retired and/or replaced. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
Affected products
Omega Solution · CoinEx Cryptopublic PoCs found — 1
cve_referencegithub.com/4m3rr0r/PoCVulDb/issues/25unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Related CVEs — Omega Solution CoinEx Crypto
In the same product, most dangerous first.
CVE-2026-105096MEDIUMOmega Solution CoinEx Crypto Customer Profile API customer authorizationEPSS 0.3%CVE-2026-105098MEDIUMOmega Solution CoinEx Crypto Support Ticket API customer information disclosureEPSS 0.3%CVE-2026-105099MEDIUMOmega Solution CoinEx Crypto Ticket Attachment Upload ticket cross site scriptingEPSS 0.2%