PatchSiren cyber security CVE debrief
CVE-2026-105099 Omega Solution CVE debrief
A weakness has been identified in Omega Solution CoinEx Crypto 2025, specifically in the file /user/ticket of the component Ticket Attachment Upload, which is vulnerable to cross-site scripting. The attack can be carried out remotely, and a public exploit is available. However, the product website no longer exists, suggesting it may have been retired or replaced. The vendor did not respond to early disclosure.
- Vendor
- Omega Solution
- Product
- CoinEx Crypto
- CVSS
- LOW 2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-04
- Original CVE updated
- 2026-10-04
- Advisory published
- 2026-10-04
- Advisory updated
- 2026-10-04
Who should care
Defenders and security teams responsible for Omega Solution CoinEx Crypto 2025 should assess exposure and prioritize patching or compensating controls if necessary. They should verify if the product is still in use, evaluate potential attack vectors, and ensure incident response plans are in place in case of a successful attack. Security teams should also monitor for potential exploitation attempts using the public exploit and review compensating controls.
Why it matters
CVE-2026-105099 is a cross-site scripting vulnerability in Omega Solution CoinEx Crypto 2025 that can be exploited remotely. While a public exploit exists, the product website is no longer available, suggesting it may be retired or replaced. Defenders should verify if the product is still in use, assess exposure, and prioritize patching or compensating controls.
- Verify if Omega Solution CoinEx Crypto 2025 is still in use and assess exposure to remote cross-site scripting attacks.
- Prioritize patching or implementing compensating controls to prevent potential remote attacks.
- Monitor for potential exploitation attempts using the public exploit.
- Ensure incident response plans are in place in case of a successful attack.
Technical summary
The vulnerability is located in the /user/ticket file of the Ticket Attachment Upload component in Omega Solution CoinEx Crypto 2025. It allows for cross-site scripting attacks to be carried out remotely. A public exploit is available, but the product website is no longer accessible. Defenders should assess the impact of the exploit and prioritize patching or compensating controls if the product is still in use. The technical details of the vulnerability are based on the CVE record and NVD entry, which provide a foundation for understanding the vulnerability's nature.
Defensive priority
Verify if the product is still in use and assess exposure; prioritize patching or compensating controls if necessary.
Recommended defensive actions
- Verify if Omega Solution CoinEx Crypto 2025 is still in use within your organization.
- Assess exposure to the vulnerable component Ticket Attachment Upload.
- Prioritize patching or implementing compensating controls if necessary.
- Monitor for potential remote attacks using the public exploit.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but the product website is no longer available. The vendor did not respond to disclosure. Defenders should verify if Omega Solution CoinEx Crypto 2025 is still in use, assess exposure to remote cross-site scripting attacks, and prioritize patching or compensating controls if necessary. The public exploit's impact and potential attack vectors should be evaluated with caution due to the product's uncertain status.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105099 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105099
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105099 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105099
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/4m3rr0r/PoCVulDb/issues/27
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/cve/CVE-2026-105099
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/894325
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/413348
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/413348/cti
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.