PatchSiren cyber security CVE debrief
CVE-2026-105097 Omega Solution CVE debrief
A vulnerability was identified in Omega Solution CoinEx Crypto 2025, impacting an unknown function of the file /customer-currency/ of the component Customer Information API. The manipulation of the argument ID leads to authorization bypass. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The product web site does not exist anymore. Maybe the product got retired and/or replaced. The vendor was contacted early about this disclosure but did not respond in any way.
- Vendor
- Omega Solution
- Product
- CoinEx Crypto
- CVSS
- LOW 2.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-04
- Original CVE updated
- 2026-10-04
- Advisory published
- 2026-10-04
- Advisory updated
- 2026-10-04
Who should care
Defenders responsible for systems using Omega Solution CoinEx Crypto 2025 should assess the potential impact of this vulnerability and prioritize verification and mitigation efforts. This includes operators, platform administrators, vulnerability management teams, and security teams who need to verify the presence of the affected product and assess the potential impact of the authorization bypass vulnerability.
Why it matters
Defenders should prioritize verifying the presence of this vulnerability in their systems and assessing the potential impact, as remote exploitation is possible and an exploit is publicly available.
- Verify the presence and impact of the authorization bypass vulnerability in Omega Solution CoinEx Crypto 2025
- Assess the potential for remote exploitation
- Monitor for publicly available exploits
Technical summary
The vulnerability is located in the /customer-currency/ file of the Customer Information API in Omega Solution CoinEx Crypto 2025. The manipulation of the ID argument allows for authorization bypass, and remote exploitation is possible. The product web site does not exist anymore. Maybe the product got retired and/or replaced. The vendor was contacted early about this disclosure but did not respond in any way. Defenders should prioritize verifying the presence of this vulnerability in their systems and assessing the potential impact.
Defensive priority
Defenders should prioritize verifying the presence of this vulnerability in their systems and assessing the potential impact.
Recommended defensive actions
- Verify the presence of Omega Solution CoinEx Crypto 2025 in your systems
- Assess the potential impact of the authorization bypass vulnerability
- Monitor for publicly available exploits
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide limited information about the vulnerability. The vendor was contacted but did not respond. Defenders should verify the presence of Omega Solution CoinEx Crypto 2025 in their systems and assess potential impact. Limited source detail is available for further verification and defensive guidance. Explicit evidence limits and defensive verification tasks are required.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105097 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105097
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105097 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105097
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/4m3rr0r/PoCVulDb/issues/25
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/cve/CVE-2026-105097
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/894322
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/413346
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/413346/cti
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.