Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 03 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 03 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | vhr through commit 03abbd3 fails to verify that the account ID in PUT /hr/pass requests belongs to the authenticated caller. Authenticated attackers can change arbitrary account passwords by supplying a target account ID and that account's current password in the request body. | |
| Title | vhr Missing Authorization in PUT /hr/pass Allows Cross-Account Password Change | |
| Weaknesses | CWE-639 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-03T14:24:15.920Z
Reserved: 2026-09-03T11:08:17.527Z
Link: CVE-2026-85182
Updated: 2026-09-03T14:24:13.368Z
Status : Received
Published: 2026-09-03T15:17:39.593
Modified: 2026-09-03T15:17:39.593
Link: CVE-2026-85182
No data.
OpenCVE Enrichment
Updated: 2026-09-03T15:30:05Z