---
id: CVE-2026-105096
title: A vulnerability was determined in Omega Solution CoinEx Crypto 2025
summary: >-
  A vulnerability was determined in Omega Solution CoinEx Crypto 2025. This
  affects an unknown function of the file /customer/ of the component Customer
  Profile API. Executing a manipulation of the argument ID can lead to
  authorization byp…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-285
  - CWE-639
vendor: Omega Solution
product: CoinEx Crypto
affected:
  - coinex_crypto 2025
published: '2026-10-04'
updated: '2026-10-04'
sourceUpdated: '2026-10-04T02:16:28.740'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105096'
references:
  - url: 'https://github.com/4m3rr0r/PoCVulDb/issues/24'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-105096'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/894320'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/413345'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/413345/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-04T01:51:38.632Z'
epss: 0.00285
epssPercentile: 0.1906
---

## Overview

A vulnerability was determined in Omega Solution CoinEx Crypto 2025. This affects an unknown function of the file /customer/ of the component Customer Profile API. Executing a manipulation of the argument ID can lead to authorization bypass. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The product web site does not exist anymore. Maybe the product got retired and/or replaced. The vendor was contacted early about this disclosure but did not respond in any way.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
