# CVE-2026-84110

## Summary

- **CVE ID:** CVE-2026-84110
- **Severity:** MEDIUM
- **CVSS Score:** 6.9 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P)
- **CWE:** CWE-602
- **Published:** Sep 1, 2026
- **Last Modified:** Sep 4, 2026

## Description

A vulnerability was detected in Releasit Releasit COD Form & Upsells v1. This vulnerability affects unknown code of the component OTP Validation. The manipulation results in client-side enforcement of server-side security. The attack may be launched remotely. The exploit is now public and may be used. Upgrading to version v2 is able to resolve this issue. The affected component should be upgraded.

## Affected Products

- Releasit — Releasit COD Form & Upsells (v1)
- Releasit — Releasit COD Form & Upsells (v2)

## References

- [CNA](https://vuldb.com/vuln/397555)
- [CNA](https://vuldb.com/vuln/397555/cti)
- [CNA](https://vuldb.com/cve/CVE-2026-84110)
- [CNA](https://vuldb.com/submit/882131)
- [CNA](https://github.com/chetansaini53/releasit-cod-otp-bypass-advisory)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.37%
- **EPSS Percentile:** 29.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._