๐Ÿ” CVE Alert

CVE-2026-86808

HIGH 7.3

moltis-org moltis vault.rs vault_recovery_handler missing authentication

CVSS Score
7.3
EPSS Score
0.0%
EPSS Percentile
0th

A security vulnerability has been detected in moltis-org moltis up to 20260818.10. The affected element is the function vault_unlock_handler/vault_recovery_handler of the file vault.rs. Such manipulation leads to missing authentication. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 20260819.01 is sufficient to fix this issue. The name of the patch is 3b92dd64d5648f829968cf48bf67dc3113852fef. Upgrading the affected component is advised.

CWE CWE-306 CWE-287
Vendor moltis-org
Product moltis
Published Sep 8, 2026
Last Updated Sep 11, 2026
Stay Ahead of the Next One

Get instant alerts for moltis-org moltis

Be the first to know when new high vulnerabilities affecting moltis-org moltis are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

moltis-org / moltis
20260818.0 20260818.1 20260818.2 20260818.3 20260818.4 20260818.5 20260818.6 20260818.7 20260818.8 20260818.9 20260818.10

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/399813 vuldb.com: https://vuldb.com/vuln/399813/cti vuldb.com: https://vuldb.com/cve/CVE-2026-86808 vuldb.com: https://vuldb.com/submit/911081 github.com: https://github.com/moltis-org/moltis/issues/1177 github.com: https://github.com/moltis-org/moltis/pull/1216 github.com: https://github.com/moltis-org/moltis/commit/3b92dd64d5648f829968cf48bf67dc3113852fef github.com: https://github.com/moltis-org/moltis/releases/tag/20260819.01 github.com: https://github.com/moltis-org/moltis/

Credits

๐Ÿ” Customeres (VulDB User)