PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-105097 Omega Solution CVE debrief

A vulnerability was identified in Omega Solution CoinEx Crypto 2025, impacting an unknown function of the file /customer-currency/ of the component Customer Information API. The manipulation of the argument ID leads to authorization bypass. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The product web site does not exist anymore. Maybe the product got retired and/or replaced. The vendor was contacted early about this disclosure but did not respond in any way.

Vendor
Omega Solution
Product
CoinEx Crypto
CVSS
LOW 2.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-04
Original CVE updated
2026-10-04
Advisory published
2026-10-04
Advisory updated
2026-10-04

Who should care

Defenders responsible for systems using Omega Solution CoinEx Crypto 2025 should assess the potential impact of this vulnerability and prioritize verification and mitigation efforts. This includes operators, platform administrators, vulnerability management teams, and security teams who need to verify the presence of the affected product and assess the potential impact of the authorization bypass vulnerability.

Why it matters

Defenders should prioritize verifying the presence of this vulnerability in their systems and assessing the potential impact, as remote exploitation is possible and an exploit is publicly available.

  • Verify the presence and impact of the authorization bypass vulnerability in Omega Solution CoinEx Crypto 2025
  • Assess the potential for remote exploitation
  • Monitor for publicly available exploits

Technical summary

The vulnerability is located in the /customer-currency/ file of the Customer Information API in Omega Solution CoinEx Crypto 2025. The manipulation of the ID argument allows for authorization bypass, and remote exploitation is possible. The product web site does not exist anymore. Maybe the product got retired and/or replaced. The vendor was contacted early about this disclosure but did not respond in any way. Defenders should prioritize verifying the presence of this vulnerability in their systems and assessing the potential impact.

Defensive priority

Defenders should prioritize verifying the presence of this vulnerability in their systems and assessing the potential impact.

Recommended defensive actions

  • Verify the presence of Omega Solution CoinEx Crypto 2025 in your systems
  • Assess the potential impact of the authorization bypass vulnerability
  • Monitor for publicly available exploits
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide limited information about the vulnerability. The vendor was contacted but did not respond. Defenders should verify the presence of Omega Solution CoinEx Crypto 2025 in their systems and assess potential impact. Limited source detail is available for further verification and defensive guidance. Explicit evidence limits and defensive verification tasks are required.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-105097 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-105097

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-105097 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105097

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.