Impact
The vulnerability is in the vault_unlock_handler/vault_recovery_handler function of the vault.rs file in the Moltis application. It allows remote callers to invoke the recovery routine without providing valid authentication, effectively bypassing the vault’s access controls. Because authentication is missing, an attacker can unlock or recover a protected vault, allowing the extraction of stored secrets or credentials. The flaw is a classic missing authentication issue, identified as CWE-287 and CWE-306.
Affected Systems
The flaw exists in Moltis versions up to and including 20260818.10. The official fix is supplied in release 20260819.01, which includes the patch commit 3b92dd64d5648f829968cf48bf67dc3113852fef. Any installation of Moltis prior to the 20260819.01 release is vulnerable.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. The EPSS score of 0.00628 (approximately 0.6%) suggests a very low current exploitation probability. Exploit prevalence data are not available, and the vulnerability is not listed in CISA’s KEV catalog, indicating no confirmed widespread attacks yet. However, the defect can be exercised remotely through exposed API endpoints, and the public disclosure of the issue creates a possibility that an attacker could leverage the flaw to read confidential vault data if the endpoint is reachable.
OpenCVE Enrichment