Authorization Bypass Vulnerability in Omega Solution CoinEx Crypto Customer Profile API
CVE-2026-105096
Key Information:
- Vendor
Omega Solution
- Status
- Vendor
- CVE Published:
- 4 October 2026
Badges
What is CVE-2026-105096?
A vulnerability has been identified in the Customer Profile API of Omega Solution CoinEx Crypto 2025, stemming from improper handling of the argument ID. This flaw can enable unauthorized remote users to bypass access controls. While the product’s official website is no longer available, indicating potential retirement or replacement, the exploit has been made publicly known, raising concerns about its potential exploitation. Attempts to notify the vendor regarding this issue went unanswered.
Affected Version(s)
CoinEx Crypto 2025
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
