CVE-2026-32865CRITICAL 9.8EPSS p22.1%

CVE-2026-32865CVE-2026-32865

Description

OPEXUS eComplaint and eCASE before version 10.1.0.0 include the secret verification code in the HTTP response when requesting a password reset via 'ForcePasswordReset.aspx'. An attacker who knows an existing user's email address can reset the user's password and security questions. Existing security questions are not asked during the process.

Scoring

CVSS 3.19.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS0.31% probability of exploitation · percentile 22.1% · 2026-06-19T12:03:05Z
Published2026-03-19
Last modified2026-03-30

Underlying weaknesses· 2

CWE-200CWE-640

References

  1. https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-26-077-01.json
  2. https://www.cve.org/CVERecord?id=CVE-2026-32865

2

TypeTargetConfidenceTier
WeaknessExposure of Sensitive Information to an Unauthorized Actorcwe-2000%live
WeaknessWeak Password Recovery Mechanism for Forgotten Passwordcwe-6400%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-32867
CVE
CVE-2025-62586
CVE
CVE-2026-22234
CVE
CVE-2026-1670
CVE
CVE-2025-48986
CVE
CVE-2026-26417
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.