Mahara before 25.04.5 and 26.04.0 is vulnerable to unauthorized access to internal accounts via Learning Tools Interoperability (LTI) under certain circumstances. This applies to LTI 1.1 and LTI 1.3 Advantage.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://mahara.org/interaction/forum/topic.php?id=10077 |
|
History
Tue, 18 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthorized Internal Account Access via LTI in Mahara |
Tue, 18 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 18 Aug 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthorized Internal Account Access via LTI in Mahara | |
| Weaknesses | CWE-284 |
Mon, 17 Aug 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mahara
Mahara mahara |
|
| Vendors & Products |
Mahara
Mahara mahara |
Mon, 17 Aug 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mahara before 25.04.5 and 26.04.0 is vulnerable to unauthorized access to internal accounts via Learning Tools Interoperability (LTI) under certain circumstances. This applies to LTI 1.1 and LTI 1.3 Advantage. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-08-17T00:00:00.000Z
Updated: 2026-08-18T12:28:29.179Z
Reserved: 2026-04-24T00:00:00.000Z
Link: CVE-2026-42163
Updated: 2026-08-18T12:27:31.693Z
Status : Deferred
Published: 2026-08-17T22:17:05.687
Modified: 2026-08-31T20:12:02.273
Link: CVE-2026-42163
No data.