Vulnerability in WonderTrader Affects Internal Limit Order Book Cache
CVE-2026-19037
Key Information:
- Vendor
WonderTrader
- Status
- Vendor
- CVE Published:
- 6 August 2026
Badges
What is CVE-2026-19037?
A weakness has been discovered in WonderTrader versions up to 0.9.9, specifically in the MatchEngine::update_lob function located in src/WtBtCore/MatchEngine.cpp. This vulnerability impacts the Internal Limit Order Book Cache Handler, potentially allowing attackers to manipulate enforcement of behavioral workflows. With remote exploitation capability publicized, this vulnerability poses a serious risk. Despite outreach to the vendor for response regarding this issue, no communication was received.
Affected Version(s)
WonderTrader 0.9.0
WonderTrader 0.9.1
WonderTrader 0.9.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
