CVE-2026-86808 Details
Description
A security vulnerability has been detected in moltis-org moltis up to 20260818.10. The affected element is the function vault_unlock_handler/vault_recovery_handler of the file vault.rs. Such manipulation leads to missing authentication. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 20260819.01 is sufficient to fix this issue. The name of the patch is 3b92dd64d5648f829968cf48bf67dc3113852fef. Upgrading the affected component is advised.
A vulnerability exists in Moltis versions through 20260818.10, where the vault management endpoints for unlocking and recovery lack proper authentication. This flaw allows unauthorized users to access these endpoints, potentially leading to the decryption of sensitive data such as provider API keys and SSH private keys. The issue has been publicly disclosed and can be exploited remotely.
Users are advised to upgrade to Moltis version 20260819.01, which includes the necessary authentication for the vault management endpoints.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 8, 2026CISA-ADP
Assessed Sep 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/moltis-org/moltis/ | [email protected] | Vendor |
| https://github.com/moltis-org/moltis/commit/3b92dd64d5648f829968cf48bf67dc3113852fef | [email protected] | Source CodeVendor |
| https://github.com/moltis-org/moltis/issues/1177 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/moltis-org/moltis/pull/1216 | [email protected] | Issue TrackingVendor |
| https://github.com/moltis-org/moltis/releases/tag/20260819.01 | [email protected] | Release NotesVendor |
| https://vuldb.com/cve/CVE-2026-86808 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/911081 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/399813 | [email protected] | BundlePermission Required |
| https://vuldb.com/vuln/399813/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| moltis-org moltis | <= 20260818.10 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 11, 2026 | CVE Modified | CISA-ADP |
| Sep 8, 2026 | New CVE Received | [email protected] |
Volerion