CVE-2026-19213: WonderTrader Pending Order TraderAdapter.h _undone_qty behavioral workflow
A vulnerability was identified in WonderTrader up to 0.9.9. Affected is the function undoneqty in the library src/WtCore/TraderAdapter.h of the component Pending Order Handler. The manipulation of the argument getUndoneQty leads to enforcement of behavioral workflow. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19213?
CVE-2026-19213 has a medium severity rating of 4.3.
How do I fix CVE-2026-19213?
To fix CVE-2026-19213, update to a version of WonderTrader that includes a patch for the _undone_qty function.
What component is affected by CVE-2026-19213?
CVE-2026-19213 affects the Pending Order Handler component in WonderTrader.
What is the potential impact of CVE-2026-19213?
CVE-2026-19213 could lead to manipulated enforcement of behavioral workflows due to argument manipulation in the _undone_qty function.
Is authentication required to exploit CVE-2026-19213?
Yes, exploitation of CVE-2026-19213 requires the attacker to have limited privileges.