What is CVE-2026-19208?
A vulnerability in WonderTrader up to version 0.9.9 allows remote manipulation of the FID_JYLB argument in the TraderDD::queryTrades function, leading to enforcement of a behavioral workflow. The attack requires high complexity. It is recommended to update to the latest version to mitigate the issue.
Azərbaycanca: WonderTrader proqramında 0.9.9 versiyasına qədər, TraderDD::queryTrades funksiyasında FID_JYLB arqumentinin manipulyasiyası nəticəsində davranış iş axınının məcburi tətbiqinə səbəb olan boşluq aşkarlanıb. Bu zəiflik uzaqdan istismar edilə bilər və yüksək mürəkkəblik tələb edir. Təsirə məruz qalmamaq üçün proqram təminatını ən son versiyaya yeniləmək tövsiyə olunur.
FAQ2
Which versions of WonderTrader are affected by CVE-2026-19208?
All versions of WonderTrader up to 0.9.9 are affected by this vulnerability.
What measure should be taken to mitigate CVE-2026-19208?
It is recommended to update the WonderTrader software to the latest version to mitigate the vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.