SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-42163

CRITICAL · CVSS 9.8 EPSS 0.33%

Source: NVD + CISA KEV + EPSS · Published 2026-08-17 · Last synced 2026-09-16

CyberRota Analysis

AI-Generated

Mahara versions prior to 25.04.5 and 26.04.0 are susceptible to unauthorized access to internal accounts through Learning Tools Interoperability (LTI) under specific conditions affecting both LTI 1.1 and LTI 1.3 Advantage. This vulnerability could allow attackers to gain access to sensitive user information and internal functionalities. Organizations using these versions of Mahara, especially those implementing LTI integrations, should prioritize applying the necessary updates to mitigate potential risks.

CVE
CVE-2026-42163
Severity
CRITICAL
CVSS
9.8
EPSS
0.33%

Original NVD Description

Mahara before 25.04.5 and 26.04.0 is vulnerable to unauthorized access to internal accounts via Learning Tools Interoperability (LTI) under certain circumstances. This applies to LTI 1.1 and LTI 1.3 Advantage.