CVE-2026-105444: dotnet eShop Ordering API OrdersApi.cs GetOrderAsync resource injection
A security flaw has been discovered in dotnet eShop .NET 8. The impacted element is the function GetOrderAsync of the file src/Ordering.API/Apis/OrdersApi.cs of the component Ordering API. Performing a manipulation of the argument OrderNumber results in improper control of resource identifiers. The attack is possible to be carried out remotely. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs network access and low-level privileges. No user interaction is required, so a remotely authenticated low-privilege user could attempt exploitation.
What is the expected impact if exploitation succeeds?
The supplied severity vector indicates low impact to confidentiality, integrity, and availability. The vulnerability affects the Ordering API's handling of the OrderNumber argument.
Is exploitation known to be practical?
The exploit maturity is rated E:P, indicating proof-of-concept exploit information is available.