CVE-2026-32865
CRITICALOPEXUS eComplaint and eCase insecure password reset
Title source: cnaDescription
OPEXUS eComplaint and eCASE before version 10.1.0.0 include the secret verification code in the HTTP response when requesting a password reset via 'ForcePasswordReset.aspx'. An attacker who knows an existing user's email address can reset the user's password and security questions. Existing security questions are not asked during the process.
Scores
CVSS v3
9.8
EPSS
0.0006
EPSS Percentile
18.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-200
CWE-640
Status
published
Products (5)
OPEXUS/eCASE
< 10.1.0.0
OPEXUS/eCASE
10.1.0.0
OPEXUS/eComplaint
< 10.1.0.0
OPEXUS/eComplaint
10.1.0.0
opexustech/ecase_ecomplaint
< 10.1.0.0
Published
Mar 19, 2026
Tracked Since
Mar 19, 2026