Description
A weakness has been identified in WonderTrader up to 0.9.9. This vulnerability affects the function MatchEngine::update_lob of the file src/WtBtCore/MatchEngine.cpp of the component Internal Limit Order Book Cache Handler. This manipulation causes enforcement of behavioral workflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-08-06
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a lack of proper authorization checks in the MatchEngine::update_lob function of the internal limit order book cache handler. An attacker who can trigger this function from an external interface can manipulate the enforcement of the behavioral workflow, effectively changing how orders are handled. This can lead to incorrect order processing, potential manipulation of order data, and disruption of the trading engine. The weakness is reflected in CWE-840 and CWE-841, indicating missing or improper authorization steps.

Affected Systems

The affected product is WonderTrader up to and including version 0.9.9. All installations of this trading software running those versions are vulnerable. No additional product variants or component versions are listed beyond the generic WonderTrader identifier.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The EPSS score is not provided, so the likelihood of exploitation in the wild cannot be quantified from the data. This vulnerability is not listed in the CISA KEV catalog. Remote exploitation is explicitly noted in the description, suggesting that the attack vector is through the system’s external interfaces. Based on the description, it is inferred that an attacker could gain remote control over the order book’s behavioral workflow and exploit this to disrupt service or modify order data.

Generated by OpenCVE AI on August 6, 2026 at 15:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WonderTrader to version 0.9.10 or later once the vendor releases a fix; confirm the vulnerability is addressed in the new release before deploying.
  • If no patch is immediately available, restrict exposure by limiting network access to the MatchEngine service to trusted internal networks and enforce strict authentication and authorization for any client capable of invoking the update_lob functionality.
  • Configure monitoring and logging to detect abnormal calls to update_lob, such as unexpected order volumes or repeated failures, and correlate with other security events to identify potential exploitation attempts.

Generated by OpenCVE AI on August 6, 2026 at 15:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 06 Aug 2026 13:15:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in WonderTrader up to 0.9.9. This vulnerability affects the function MatchEngine::update_lob of the file src/WtBtCore/MatchEngine.cpp of the component Internal Limit Order Book Cache Handler. This manipulation causes enforcement of behavioral workflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Title WonderTrader Internal Limit Order Book Cache MatchEngine.cpp update_lob behavioral workflow
First Time appeared Wondertrader
Wondertrader wondertrader
Weaknesses CWE-840
CWE-841
CPEs cpe:2.3:a:wondertrader:wondertrader:*:*:*:*:*:*:*:*
Vendors & Products Wondertrader
Wondertrader wondertrader
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Wondertrader Wondertrader
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-06T13:50:39.568Z

Reserved: 2026-08-06T05:50:55.346Z

Link: CVE-2026-19037

cve-icon Vulnrichment

Updated: 2026-08-06T13:50:37.084Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T15:15:12Z

Weaknesses