Home

Description

OPEXUS eComplaint and eCASE before version 10.1.0.0 include the secret verification code in the HTTP response when requesting a password reset via 'ForcePasswordReset.aspx'. An attacker who knows an existing user's email address can reset the user's password and security questions. Existing security questions are not asked during the process.

PUBLISHED Reserved 2026-03-16 | Published 2026-03-19 | Updated 2026-03-19 | Assigner cisa-cg




CRITICAL: 9.2CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CRITICAL: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

CWE-640 Weak Password Recovery Mechanism for Forgotten Password

Product status

Default status
affected

Any version before 10.1.0.0
affected

10.1.0.0
unaffected

Default status
affected

Any version before 10.1.0.0
affected

10.1.0.0
unaffected

Credits

Adam Rose, CISA

References

raw.githubusercontent.com/...IT/white/2025/va-26-077-01.json (url)

www.cve.org/CVERecord?id=CVE-2026-32865 (url)

cve.org (CVE-2026-32865)

nvd.nist.gov (CVE-2026-32865)

Download JSON