Description
A security vulnerability has been detected in moltis-org moltis up to 20260818.10. The affected element is the function vault_unlock_handler/vault_recovery_handler of the file vault.rs. Such manipulation leads to missing authentication. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 20260819.01 is sufficient to fix this issue. The name of the patch is 3b92dd64d5648f829968cf48bf67dc3113852fef. Upgrading the affected component is advised.
Published: 2026-09-08
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access
Action: Patch Now
AI Analysis

Impact

The vulnerability is in the vault_unlock_handler/vault_recovery_handler function of the vault.rs file in the Moltis application. It allows remote callers to invoke the recovery routine without providing valid authentication, effectively bypassing the vault’s access controls. Because authentication is missing, an attacker can unlock or recover a protected vault, allowing the extraction of stored secrets or credentials. The flaw is a classic missing authentication issue, identified as CWE-287 and CWE-306.

Affected Systems

The flaw exists in Moltis versions up to and including 20260818.10. The official fix is supplied in release 20260819.01, which includes the patch commit 3b92dd64d5648f829968cf48bf67dc3113852fef. Any installation of Moltis prior to the 20260819.01 release is vulnerable.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity. The EPSS score of 0.00628 (approximately 0.6%) suggests a very low current exploitation probability. Exploit prevalence data are not available, and the vulnerability is not listed in CISA’s KEV catalog, indicating no confirmed widespread attacks yet. However, the defect can be exercised remotely through exposed API endpoints, and the public disclosure of the issue creates a possibility that an attacker could leverage the flaw to read confidential vault data if the endpoint is reachable.

Generated by OpenCVE AI on September 9, 2026 at 15:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official patch commit 3b92dd64d5648f829968cf48bf67dc3113852fef or upgrade the Moltis component to release 20260819.01.
  • Restrict network access to the vault API endpoints so that only trusted hosts with proper credentials can reach them.
  • Disable the vault_recovery_handler API endpoint via application configuration or firewall rules until the component is fully patched.

Generated by OpenCVE AI on September 9, 2026 at 15:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in moltis-org moltis up to 20260818.10. The affected element is the function vault_unlock_handler/vault_recovery_handler of the file vault.rs. Such manipulation leads to missing authentication. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 20260819.01 is sufficient to fix this issue. The name of the patch is 3b92dd64d5648f829968cf48bf67dc3113852fef. Upgrading the affected component is advised.
Title moltis-org moltis vault.rs vault_recovery_handler missing authentication
First Time appeared Moltis-org
Moltis-org moltis
Weaknesses CWE-287
CWE-306
CPEs cpe:2.3:a:moltis-org:moltis:*:*:*:*:*:*:*:*
Vendors & Products Moltis-org
Moltis-org moltis
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Moltis-org Moltis
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-11T20:34:12.343Z

Reserved: 2026-09-08T13:10:12.053Z

Link: CVE-2026-86808

cve-icon Vulnrichment

Updated: 2026-09-11T20:02:43.713Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T20:18:54.253

Modified: 2026-09-11T21:17:49.870

Link: CVE-2026-86808

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T15:45:16Z

Weaknesses
  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function