CVE-2026-105444
CVE-2026-105444 is a medium-severity vulnerability with a CVSS 3.x base score of 6.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-99.
Key facts
- Severity: Medium (CVSS 3.x base score 6.3)
- CVSS v2: 6.5
- CVSS v4: 2.1
- EPSS exploit prediction: 0% (13th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-99
- Published:
- Last modified:
Description
A security flaw has been discovered in dotnet eShop .NET 8. The impacted element is the function GetOrderAsync of the file src/Ordering.API/Apis/OrdersApi.cs of the component Ordering API. Performing a manipulation of the argument OrderNumber results in improper control of resource identifiers. The attack is possible to be carried out remotely. The project was informed of the problem early through an issue report but has not responded yet.
Frequently asked questions
- What is CVE-2026-105444?
- A security flaw has been discovered in dotnet eShop .NET 8. The impacted element is the function GetOrderAsync of the file src/Ordering.API/Apis/OrdersApi.cs of the component Ordering API. Performing a manipulation of the argument OrderNumber results in improper control of resource identifiers. The attack is possible to be carried out remotely. The project was informed of the problem early through an issue report but has not responded yet.
- How severe is CVE-2026-105444?
- CVE-2026-105444 has a CVSS 3.x base score of 6.3, rated medium severity. It is exploitable over network with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is low, integrity low, and availability low.
- Is CVE-2026-105444 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (13th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-105444?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-105444 published?
- CVE-2026-105444 was published on 2026-10-05 and last updated on 2026-10-06.
References
- https://github.com/dotnet/eShop/
- https://github.com/dotnet/eShop/issues/996
- https://vuldb.com/cve/CVE-2026-105444
- https://vuldb.com/submit/984283
- https://vuldb.com/vuln/413608
- https://vuldb.com/vuln/413608/cti
Other CWE-99 vulnerabilities
- CVE-2025-43491 — Critical (CVSS 9.8): A vulnerability in the Poly Lens Desktop application running on the Windows platform might allow modifications to the…
- CVE-2017-5159 — Critical (CVSS 9.8): An issue was discovered on Phoenix Contact mGuard devices that have been updated to Version 8.4.0. When updating an…
- CVE-2025-2410 — Critical (CVSS 9.1): Port manipulation vulnerabilities in ASPECT provide attackers with the ability to con-trol TCP/IP port access if…
- CVE-2025-0756 — Critical (CVSS 9.1): Overview The product receives input from an upstream component, but it does not restrict or incorrectly…
- CVE-2024-57971 — Critical (CVSS 9.1): DataSourceResource.java in the SpagoBI API support in Knowage Server in KNOWAGE before 8.1.30 does not ensure that…
- CVE-2024-5706 — High (CVSS 8.8): The product receives input from an upstream component, but it does not restrict or incorrectly restricts the input…