CVE-2026-19212
CVE-2026-19212 is a medium-severity vulnerability with a CVSS 3.x base score of 4.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-453.
Key facts
- Severity: Medium (CVSS 3.x base score 4.3)
- CVSS v2: 4.0
- CVSS v4: 2.1
- EPSS exploit prediction: 0% (19th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-453
- Published:
- Last modified:
Description
A vulnerability was determined in WonderTrader up to 0.9.9. This impacts an unknown function of the file src/Includes/WTSTradeDef.hpp of the component TraderATP Cash Trade Conversion. Executing a manipulation of the argument m_offsetType can lead to use of uninitialized variable. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Frequently asked questions
- What is CVE-2026-19212?
- A vulnerability was determined in WonderTrader up to 0.9.9. This impacts an unknown function of the file src/Includes/WTSTradeDef.hpp of the component TraderATP Cash Trade Conversion. Executing a manipulation of the argument m_offsetType can lead to use of uninitialized variable. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
- How severe is CVE-2026-19212?
- CVE-2026-19212 has a CVSS 3.x base score of 4.3, rated medium severity. It is exploitable over network with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is none, integrity none, and availability low.
- Is CVE-2026-19212 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (19th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-19212?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-19212 published?
- CVE-2026-19212 was published on 2026-08-07 and last updated on 2026-08-12.
References
- https://my.feishu.cn/wiki/PyAuwg8Bwit3TBk5DgLc14Ghnkb?from=from_copylink
- https://vuldb.com/cve/CVE-2026-19212
- https://vuldb.com/submit/864875
- https://vuldb.com/vuln/386957
- https://vuldb.com/vuln/386957/cti
Other CWE-453 vulnerabilities
- CVE-2021-27426 — Critical (CVSS 9.8): GE UR IED firmware versions prior to version 8.1x with “Basic” security variant does not allow the disabling of the…
- CVE-2024-21411 — High (CVSS 8.8): Skype for Consumer Remote Code Execution Vulnerability
- CVE-2022-3262 — High (CVSS 8.1): A flaw was found in Openshift. A pod with a DNSPolicy of "ClusterFirst" may incorrectly resolve the hostname based on a…
- CVE-2026-0082 — High (CVSS 7.8): In tryStartActivity of NfcDispatcher.java, there is a possible automatic special app access permission assignment due…
- CVE-2025-48563 — High (CVSS 7.8): In onNullBinding of RemoteFillService.java, there is a possible background activity launch due to an insecure default…
- CVE-2024-41255 — High (CVSS 7.5): filestash v0.4 is configured to skip TLS certificate verification when using the FTPS protocol, possibly allowing…