CVE-2026-105098

Executive Summary

CVE-2026-105098 exposes an information‑disclosure vulnerability in the Support Ticket API of Omega Solution CoinEx Crypto 2025. By manipulating the status, page, or count parameters in /ticket/customer, an attacker can retrieve sensitive data remotely. The flaw is publicly available, yet the product’s website is defunct and the vendor has not responded. The issue remains unlisted in CISA KEV.


Authoritative CVE Metadata - CVSS Base Score: 4.3 (MEDIUM) - Published: 2026-10-04T04:16:36.140 - Last Modified: 2026-10-04T04:16:36.140

Original Description: A security flaw has been discovered in Omega Solution CoinEx Crypto 2025. Affected is an unknown function of the file /ticket/customer of the component Support Ticket API. The manipulation of the argument status/page/count results in information disclosure. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The product web site does not exist anymore. Maybe the product got retired and/or replaced. The vendor was contacted early about this disclosure but did not respond in any way.

"The greatest danger for most of us is not that our aim is too high and we miss it, but that it is too low and we reach it."

— Michelangelo
Source: NVD