---
id: CVE-2026-86808
title: >-
  A security vulnerability has been detected in moltis-org moltis up to
  20260818.10
summary: >-
  A security vulnerability has been detected in moltis-org moltis up to
  20260818.10. The affected element is the function
  vault_unlock_handler/vault_recovery_handler of the file vault.rs. Such
  manipulation leads to missing authentication. …
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-287
  - CWE-306
vendor: moltis-org
product: moltis
affected:
  - moltis 20260818.0
  - moltis 20260818.1
  - moltis 20260818.2
  - moltis 20260818.3
  - moltis 20260818.4
  - moltis 20260818.5
  - moltis 20260818.6
  - moltis 20260818.7
  - moltis 20260818.8
  - moltis 20260818.9
  - moltis 20260818.10
published: '2026-09-08'
updated: '2026-09-11'
sourceUpdated: '2026-09-11T21:17:49.870'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86808'
references:
  - url: 'https://github.com/moltis-org/moltis/'
    label: cna@vuldb.com
  - url: >-
      https://github.com/moltis-org/moltis/commit/3b92dd64d5648f829968cf48bf67dc3113852fef
    label: cna@vuldb.com
  - url: 'https://github.com/moltis-org/moltis/issues/1177'
    label: cna@vuldb.com
  - url: 'https://github.com/moltis-org/moltis/pull/1216'
    label: cna@vuldb.com
  - url: 'https://github.com/moltis-org/moltis/releases/tag/20260819.01'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-86808'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/911081'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/399813'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/399813/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-11T20:02:42.728233Z'
epss: 0.00838
epssPercentile: 0.56015
ingestedAt: '2026-09-08T20:10:03.221Z'
---

## Overview

A security vulnerability has been detected in moltis-org moltis up to 20260818.10. The affected element is the function vault_unlock_handler/vault_recovery_handler of the file vault.rs. Such manipulation leads to missing authentication. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 20260819.01 is sufficient to fix this issue. The name of the patch is 3b92dd64d5648f829968cf48bf67dc3113852fef. Upgrading the affected component is advised.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
