CVE-2026-84110
Received Received - Intake

Client-Side Enforcement Flaw in Releasit COD Form & Upsells

Vulnerability report for CVE-2026-84110, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: VulDB

Description

A vulnerability was detected in Releasit Releasit COD Form & Upsells v1. This vulnerability affects unknown code of the component OTP Validation. The manipulation results in client-side enforcement of server-side security. The attack may be launched remotely. The exploit is now public and may be used. Upgrading to version v2 is able to resolve this issue. The affected component should be upgraded.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-01
AI Q&A
2026-09-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
releasit releasit_cod_form_and_upsells 1
releasit releasit_cod_form_and_upsells From 2 (inc)
releasit releasit_cod_form_and_upsells to 2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-602 The product is composed of a server that relies on the client to implement a mechanism that is intended to protect the server.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in Releasit COD Form & Upsells v1, specifically in the OTP Validation component. It allows attackers to bypass server-side security checks by manipulating client-side behavior. The issue arises because the server does not properly enforce security rules, relying instead on the client to validate them.

Detection Guidance

Check if the Releasit COD Form & Upsells app is installed and inspect its JavaScript bundle for hardcoded symmetric keys or client-side OTP validation logic. Review network traffic for OTP bypass attempts or unusual Cash-on-Delivery order patterns.

Impact Analysis

An attacker could exploit this to bypass intended security controls, potentially allowing unauthorized actions or data access. Since the exploit is public, the risk is higher. Upgrading to version v2 is recommended to resolve the issue.

Compliance Impact

This vulnerability could lead to unauthorized data access or actions, violating confidentiality and integrity requirements in GDPR and HIPAA. Compliance may be compromised if sensitive data is exposed or altered due to the lack of proper server-side validation.

Mitigation Strategies

Upgrade the Releasit COD Form & Upsells app to version v2 or later, which resolves the OTP validation flaw. Ensure OTP verification is enforced server-side and remove any hardcoded secrets from the application.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84110. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart