Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-223g-f5mq-gw33 | OpenLearnX: Critical Authentication Bypass via JWT Signature Verification Disabled Leading to Account Takeover |
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 28 May 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Th30d4y
Th30d4y openlearnx |
|
| Vendors & Products |
Th30d4y
Th30d4y openlearnx |
Wed, 27 May 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenLearnX is an open-source, decentralized learning and assessment platform. Prior to 2.0.4, a critical authentication vulnerability was identified in OpenLearnX that could allow unauthorized access to user accounts under specific conditions. This vulnerability is fixed in 2.0.4. | |
| Title | OpenLearnX: Critical Authentication Bypass via JWT Signature Verification Disabled Leading to Account Takeover | |
| Weaknesses | CWE-287 CWE-347 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-02T18:09:07.056Z
Reserved: 2026-05-07T18:04:17.308Z
Link: CVE-2026-44720
Updated: 2026-06-02T18:08:53.861Z
Status : Deferred
Published: 2026-05-27T22:16:36.680
Modified: 2026-06-17T10:51:16.503
Link: CVE-2026-44720
No data.
OpenCVE Enrichment
Updated: 2026-05-28T03:00:05Z
Github GHSA