Description
A vulnerability was identified in Omega Solution CoinEx Crypto 2025. This impacts an unknown function of the file /customer-currency/ of the component Customer Information API. The manipulation of the argument ID leads to authorization bypass. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The product web site does not exist anymore. Maybe the product got retired and/or replaced. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-10-04
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Access via Authorization Bypass
Action: Patch
AI Analysis

Impact

The vulnerability resides in the Customer Information API's /customer-currency/ component of Omega Solution:CoinEx Crypto 2025. Manipulating the ID parameter allows an attacker to bypass normal authorization checks, gaining unauthorized access to customer currency data. This issue is classified as an authorization bypass; the attacker can obtain or modify data that should be protected. The vulnerability is identified as CWE-285 and CWE-639.

Affected Systems

Omega Solution's CoinEx Crypto platform, version 2025. The specific affected module is the customer-currency endpoint of the Customer Information API. The product has been discontinued or replaced and the vendor's website no longer exists, making upgrade paths unclear.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. EPSS is not available, but publicly available exploit code suggests the risk is real. The vulnerability is usable remotely through the API, and no remediation is currently published. It is not listed in the CISA KEV catalog, but due to the public exploit and remote nature it should be treated with urgency.

Generated by OpenCVE AI on October 4, 2026 at 03:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any available vendor patch or newer version that addresses the authorization bypass if released.
  • Restrict access to the /customer-currency/ API endpoint to trusted IP ranges or enforce stricter authentication before parameter validation.
  • Monitor API logs for suspicious ID parameter values and anomalous access patterns.

Generated by OpenCVE AI on October 4, 2026 at 03:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 04 Oct 2026 02:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in Omega Solution CoinEx Crypto 2025. This impacts an unknown function of the file /customer-currency/ of the component Customer Information API. The manipulation of the argument ID leads to authorization bypass. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The product web site does not exist anymore. Maybe the product got retired and/or replaced. The vendor was contacted early about this disclosure but did not respond in any way.
Title Omega Solution CoinEx Crypto Customer Information API customer-currency authorization
First Time appeared Omega Solution
Omega Solution coinex Crypto
Weaknesses CWE-285
CWE-639
CPEs cpe:2.3:a:omega_solution:coinex_crypto:*:*:*:*:*:*:*:*
Vendors & Products Omega Solution
Omega Solution coinex Crypto
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Omega Solution Coinex Crypto
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-04T02:00:11.654Z

Reserved: 2026-10-03T09:42:57.966Z

Link: CVE-2026-105097

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-04T03:16:49.460

Modified: 2026-10-04T03:16:49.460

Link: CVE-2026-105097

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-04T03:30:06Z

Weaknesses
  • CWE-285

    Improper Authorization

  • CWE-639

    Authorization Bypass Through User-Controlled Key