Loading market data...
← Back to CVE feed

CVE-2026-42163

CRITICAL CVSS 9.8 View on NVD ↗

Description

Mahara before 25.04.5 and 26.04.0 is vulnerable to unauthorized access to internal accounts via Learning Tools Interoperability (LTI) under certain circumstances. This applies to LTI 1.1 and LTI 1.3 Advantage.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published: Aug 17, 2026 22:17 UTC Modified: Aug 18, 2026 13:17 UTC