cvedb.io
CVE-2026-32865
CRITICAL · CVSS 9.8
EPSS exploitation probability: 0%
Published 2026-03-19T16:16:03.260 · Last modified 2026-06-17T10:36:28.380

Summary

OPEXUS eComplaint and eCASE before version 10.1.0.0 include the secret verification code in the HTTP response when requesting a password reset via 'ForcePasswordReset.aspx'. An attacker who knows an existing user's email address can reset the user's password and security questions. Existing security questions are not asked during the process.

Affected products

opexustech — ecase_ecomplaint

Does this affect you?

Add your gear to cvedb and we'll alert you only when opexustech ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.