Junglewise Threat Intelligence

CVE-2026-86808: moltis vault unlock authentication bypass

CVE-2026-86808 · Severity: high · CVSS 7.3 · Published 2026-09-08

Executive brief

moltis is a secure agent server that stores sensitive data including provider keys, SSH private keys, environment variables, and authentication tokens in an encrypted vault. An authentication bypass vulnerability in the vault unlock and recovery functions allowed attackers to access and decrypt all stored secrets remotely without proper authentication, potentially exposing credentials across multiple services.

Technical details

A missing authentication vulnerability exists in the vault_unlock_handler and vault_recovery_handler functions in vault.rs of moltis. The affected endpoints (under /api/auth/) were incorrectly allowlisted as public paths, permitting unauthenticated remote callers to invoke vault unsealing operations. Unsealing the vault decrypts all stored secrets including provider credentials, SSH keys, and service tokens. The vulnerability requires no authentication or user interaction and was publicly disclosed before a patch became available. The fix (commit 3b92dd64d5648f829968cf48bf67dc3113852fef) requires proper authentication by adding AuthSession validation to these critical endpoints.

Affected products

  • moltis-org moltis up to 20260818.10

Timeline

  • 2026-09-08: disclosed: Vulnerability publicly disclosed
  • 2026-08-19: patched: Fix available in version 20260819.01 (commit 3b92dd64d5648f829968cf48bf67dc3113852fef)

References