Description
A security flaw has been discovered in dotnet eShop .NET 8. The impacted element is the function GetOrderAsync of the file src/Ordering.API/Apis/OrdersApi.cs of the component Ordering API. Performing a manipulation of the argument OrderNumber results in improper control of resource identifiers. The attack is possible to be carried out remotely. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-10-05
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Resource Access
Action: Assess Impact
AI Analysis

Impact

The flaw resides in the GetOrderAsync function of the Ordering API within the dotnet eShop project. By manipulating the OrderNumber argument, a requester can control resource identifiers in an improper manner, enabling a form of resource injection that falls under CWE-99. This allows an attacker to request data for arbitrary orders or resources that should be otherwise inaccessible, potentially exposing sensitive information or disrupting normal service.

Affected Systems

dotnet eShop (Ordering API) built on .NET 8. The vulnerable code is located in src/Ordering.API/Apis/OrdersApi.cs and is part of the dotnet eShop repository. Affected version information is not available.

Risk and Exploitability

The CVSS score is 5.3, indicating moderate risk. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been widely exploited. The attack can be carried out remotely by providing a crafted OrderNumber value to the Orders API endpoint. Because the impact involves unauthorized access to order resources, the potential for data leakage or service disruption exists, especially if it is inferred that authentication or input validation controls are weak or absent.

Generated by OpenCVE AI on October 5, 2026 at 23:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any vendor‑issued patch or update for dotnet eShop Ordering API as soon as it becomes available.
  • Implement strict input validation on the OrderNumber parameter, ensuring that only valid, authenticated order identifiers are accepted.
  • Enforce proper authentication and authorization checks for the Orders API endpoint, so that only users with appropriate permissions can retrieve order details.

Generated by OpenCVE AI on October 5, 2026 at 23:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 21:15:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in dotnet eShop .NET 8. The impacted element is the function GetOrderAsync of the file src/Ordering.API/Apis/OrdersApi.cs of the component Ordering API. Performing a manipulation of the argument OrderNumber results in improper control of resource identifiers. The attack is possible to be carried out remotely. The project was informed of the problem early through an issue report but has not responded yet.
Title dotnet eShop Ordering API OrdersApi.cs GetOrderAsync resource injection
First Time appeared Dotnet
Dotnet eshop
Weaknesses CWE-99
CPEs cpe:2.3:a:dotnet:eshop:*:*:*:*:*:*:*:*
Vendors & Products Dotnet
Dotnet eshop
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-05T21:00:14.065Z

Reserved: 2026-10-05T13:20:35.856Z

Link: CVE-2026-105444

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T21:16:34.470

Modified: 2026-10-05T21:16:34.470

Link: CVE-2026-105444

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T23:30:15Z

Weaknesses
  • CWE-99

    Improper Control of Resource Identifiers ('Resource Injection')