CVE-2026-86808
moltis-org moltis vault.rs vault_recovery_handler missing authentication
CVSS Score
7.3
EPSS Score
0.0%
EPSS Percentile
0th
A security vulnerability has been detected in moltis-org moltis up to 20260818.10. The affected element is the function vault_unlock_handler/vault_recovery_handler of the file vault.rs. Such manipulation leads to missing authentication. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 20260819.01 is sufficient to fix this issue. The name of the patch is 3b92dd64d5648f829968cf48bf67dc3113852fef. Upgrading the affected component is advised.
| CWE | CWE-306 CWE-287 |
| Vendor | moltis-org |
| Product | moltis |
| Published | Sep 8, 2026 |
| Last Updated | Sep 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for moltis-org moltis
Be the first to know when new high vulnerabilities affecting moltis-org moltis are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
moltis-org / moltis
20260818.0 20260818.1 20260818.2 20260818.3 20260818.4 20260818.5 20260818.6 20260818.7 20260818.8 20260818.9 20260818.10
References
vuldb.com: https://vuldb.com/vuln/399813 vuldb.com: https://vuldb.com/vuln/399813/cti vuldb.com: https://vuldb.com/cve/CVE-2026-86808 vuldb.com: https://vuldb.com/submit/911081 github.com: https://github.com/moltis-org/moltis/issues/1177 github.com: https://github.com/moltis-org/moltis/pull/1216 github.com: https://github.com/moltis-org/moltis/commit/3b92dd64d5648f829968cf48bf67dc3113852fef github.com: https://github.com/moltis-org/moltis/releases/tag/20260819.01 github.com: https://github.com/moltis-org/moltis/
Credits
๐ Customeres (VulDB User)