Back to overview

CVE-2026-32865

CRITICAL
9.8
CVSS 3.1
Description
OPEXUS eComplaint and eCASE before version 10.1.0.0 include the secret verification code in the HTTP response when requesting a password reset via 'ForcePasswordReset.aspx'. An attacker who knows an existing user's email address can reset the user's password and security questions. Existing security questions are not asked during the process.

Metadata

CVE ID
CVE-2026-32865
State
PUBLISHED
Assigner
cisa-cg
Reserved
2026-03-16 20:57 UTC
Published
2026-03-19 15:47 UTC
Last updated
2026-03-19 18:20 UTC
Primary CWE
CWE-200
CWE-200 Exposure of Sensitive Information to an Unauthorized…
Vendor / Product
OPEXUS / eComplaint
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
total
Affected products (2)
VendorProductPlatformVersions
OPEXUS eCASE 0 < 10.1.0.0, 10.1.0.0
OPEXUS eComplaint 0 < 10.1.0.0, 10.1.0.0
Weakness (CWE)
CWESourceDescription
CWE-200 cna CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
CWE-640 cna CWE-640 Weak Password Recovery Mechanism for Forgotten Password
CVSS scores (2)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.2 CRITICAL 4.0 cna CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Back to overview