CVE-2026-86808

Source
https://cve.org/CVERecord?id=CVE-2026-86808
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-86808.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-86808
Published
2026-09-08T19:30:11Z
Modified
2026-09-10T03:48:30Z
Severity
  • 5.5 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
moltis-org moltis vault.rs vault_recovery_handler missing authentication
Details

A security vulnerability has been detected in moltis-org moltis up to 20260818.10. The affected element is the function vault_unlock_handler/vault_recovery_handler of the file vault.rs. Such manipulation leads to missing authentication. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 20260819.01 is sufficient to fix this issue. The name of the patch is 3b92dd64d5648f829968cf48bf67dc3113852fef. Upgrading the affected component is advised.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-287",
        "CWE-306"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86808.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "20260818.0"
                },
                {
                    "last_affected": "20260818.0"
                },
                {
                    "introduced": "20260818.2"
                },
                {
                    "last_affected": "20260818.2"
                },
                {
                    "introduced": "20260818.3"
                },
                {
                    "last_affected": "20260818.3"
                },
                {
                    "introduced": "20260818.4"
                },
                {
                    "last_affected": "20260818.4"
                },
                {
                    "introduced": "20260818.5"
                },
                {
                    "last_affected": "20260818.5"
                },
                {
                    "introduced": "20260818.6"
                },
                {
                    "last_affected": "20260818.6"
                },
                {
                    "introduced": "20260818.7"
                },
                {
                    "last_affected": "20260818.7"
                },
                {
                    "introduced": "20260818.8"
                },
                {
                    "last_affected": "20260818.8"
                },
                {
                    "introduced": "20260818.9"
                },
                {
                    "last_affected": "20260818.9"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/moltis-org/moltis

Affected ranges

Type
GIT
Repo
https://github.com/moltis-org/moltis
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "20260818.1"
        },
        {
            "last_affected": "20260818.1"
        },
        {
            "introduced": "20260818.10"
        },
        {
            "last_affected": "20260818.10"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

20260818.*
20260818.1
20260818.10

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-86808.json"