CVE-2026-32865Disclosure(opexustech / ecase_ecomplaint)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OPEXUS eComplaint and eCASE before version 10.1.0.0 include the secret verification code in the HTTP response when requesting a password reset via 'ForcePasswordReset.aspx'. An attacker who knows an existing user's email address can reset the user's password and security questions. Existing security questions are not asked during the process.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200CWE-640

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ecase_ecomplaint

Threat summary

  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • Peaked 1d ago at 4 mentions (2026-03-19); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
ecase_ecomplaint

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-03-19: 4Mentions · 2026-03-23: 1Technical Details · 2026-03-19: 4Technical Details · 2026-03-23: 103-1903-23
Signal classification1 categories
Disclosure
5100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-194
Disclosure4
2026-03-231
Disclosure1
Full discourse5 posts
  • Joel Vázquez Ortiz@_substrg_
    Disclosure

    #infosec #cybersecurity Critical! CVE-2026-32865 OPEXUS eComplaint and eCase insecure password reset

    Post summary

    A critical vulnerability (CVE-2026-32865) in OPEXUS eComplaint and eCase is reported, identified as an insecure password reset flaw, with no further exploitation or mitigation details provided.

    1000047
    79 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32865 OPEXUS eComplaint and eCASE before version 10.1.0.0 include the secret verification code in the HTTP response when requesting a password reset via 'ForcePasswordReset… https://www.cve.org/CVERecord?id=CVE-2026-32865

    Post summary

    The text announces a new information‑disclosure vulnerability (CVE‑2026‑32865) in OPEXUS eComplaint and eCASE (prior to version 10.1.0.0), where secret verification codes appear in HTTP responses during a forced password reset.

    0000097
    56.8K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-32865 - Critical OPEXUS eComplaint and eCASE before version 10.1.0.0 include the secret verification code in the HTTP response when requesting a password reset via 'ForcePasswordReset.aspx'. An attacker w... https://www.thehackerwire.com/vulnerability/CVE-2026-32865/ https://t.co/9ff5VoBmPU

    Post summary

    The tweet announces CVE‑2026‑32865 as a critical flaw where the secret verification code leaks in the HTTP response during password reset in OPEXUS eComplaint and eCASE versions before 10.1.0.0; it includes technical details but no PoC, exploit, or patch information.

    0000054
    137 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-32865: CRITICAL] Warning: OPEXUS eComplaint & eCASE <10.1.0.0 reveal secret codes in HTTP responses for password resets. Attackers with email addresses can bypass security questions.#cve,CVE-2026-32865,#cybersecurity https://cvefind.com/CVE-2026-32865

    Post summary

    The post announces a critical vulnerability (CVE‑2026‑32865) in OPEXUS eComplaint & eCASE (<10.1.0.0) that leaks secret codes in HTTP responses, allowing attackers to bypass password‑reset security questions, yet it offers no PoC, exploit, or patch details.

    0000049
    603 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-32865: OPEXUS eComplaint and eCase inse... Password reset tokens leaked in HTTP response body - just enumerate emails and you own every account, no questions aske... https://zerodaysignal.com/vulnerability/CVE-2026-32865 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE-2026-32865, describing how password reset tokens are leaked in HTTP responses, enabling an attacker to enumerate emails and take over accounts; no PoC, patch, or active exploitation details are provided.

    0000064
    154 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopexustechecase_ecomplaint---

Explore more