A vulnerability was identified in Omega Solution CoinEx Crypto 2025. (CVE-2026-105097)
Description
A vulnerability was identified in Omega Solution CoinEx Crypto 2025. This impacts an unknown function of the file /customer-currency/ of the component Customer Information API. The manipulation of the argument ID leads to authorization bypass. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The product web site does not exist anymore. Maybe the product got retired and/or replaced. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS v3.1
Score 4.3medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-105097 describes an authorization bypass vulnerability in Omega Solution CoinEx Crypto 2025. The flaw exists in an unspecified function of the /customer-currency/ file within the Customer Information API component. By manipulating the ID argument, an attacker can bypass authorization controls remotely. Exploit code is publicly available, but the vendor has not provided any response or patch, and the product website is defunct.
Potential Impact
The vulnerability allows an attacker with network access and low privileges to bypass authorization controls, potentially gaining unauthorized access to customer currency information. The impact is limited to confidentiality (partial information disclosure) with no integrity or availability impact reported. The overall severity is low based on the CVSS score of 4.3.
Mitigation Recommendations
No official patch or remediation is available as the vendor has not responded and the product appears to be retired or replaced. Users should consider discontinuing use of the affected product or implementing compensating controls such as network access restrictions to the vulnerable API. Monitor for any updates from the vendor or community regarding fixes.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-v3m5-f97j-j2pm
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-105097"]
- Database Specific Severity
- LOW
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ac245df12601ec6a31684d6
Added to database: 10/04/2026, 12:26:07 UTC
Last enriched: 10/04/2026, 13:23:42 UTC
Last updated: 10/04/2026, 16:06:06 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.