CVE-2026-32865: OPEXUS eComplaint and eCase insecure password reset
OPEXUS eComplaint and eCASE before version 10.1.0.0 include the secret verification code in the HTTP response when requesting a password reset via 'ForcePasswordReset.aspx'. An attacker who knows an existing user's email address can reset the user's password and security questions. Existing security questions are not asked during the process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32865?
CVE-2026-32865 is considered a high severity vulnerability due to the risk of unauthorized password resets.
How do I fix CVE-2026-32865?
To fix CVE-2026-32865, upgrade OPEXUS eComplaint and eCase to version 10.1.0.0 or later.
What systems are affected by CVE-2026-32865?
CVE-2026-32865 affects OPEXUS eComplaint and eCase versions prior to 10.1.0.0.
Can an attacker exploit CVE-2026-32865 easily?
Yes, an attacker can exploit CVE-2026-32865 easily if they know an existing user's email address.
What impact does CVE-2026-32865 have on users?
CVE-2026-32865 allows an attacker to reset passwords and potentially gain unauthorized access to user accounts.