PatchSiren cyber security CVE debrief
CVE-2026-44720 th30d4y CVE debrief
OpenLearnX versions prior to 2.0.4 contain a critical authentication vulnerability that could allow unauthorized account access under specific conditions. The vulnerability involves weaknesses in authentication mechanisms (CWE-287) and improper verification of cryptographic signatures (CWE-347). The issue was disclosed on 2026-05-27 and has been resolved in version 2.0.4. No known exploitation in ransomware campaigns has been reported.
- Vendor
- th30d4y
- Product
- OpenLearnX
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-27
- Original CVE updated
- 2026-05-29
- Advisory published
- 2026-05-27
- Advisory updated
- 2026-05-29
Who should care
Organizations running OpenLearnX learning platform instances, particularly those with sensitive educational or assessment data requiring strong authentication controls.
Technical summary
OpenLearnX prior to 2.0.4 contains authentication weaknesses (CWE-287, CWE-347) enabling unauthorized account access. Network-exploitable with low complexity. Fixed in 2.0.4.
Defensive priority
medium
Recommended defensive actions
- Upgrade OpenLearnX to version 2.0.4 or later to remediate the authentication vulnerability
- Review authentication and cryptographic signature verification implementations for defense-in-depth
- Monitor for unauthorized access attempts in authentication logs
- Verify integrity of user session management following the advisory guidance
Evidence notes
The CVE description indicates this is a critical authentication vulnerability allowing unauthorized account access. CVSS 4.0 vector shows network attack vector with low attack complexity, no privileges required, and low integrity impact. Weaknesses identified as CWE-287 (Improper Authentication) and CWE-347 (Improper Verification of Cryptographic Signature). Fix version 2.0.4 confirmed in advisory.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-44720 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-44720
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-44720 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-44720
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/th30d4y/OpenLearnX/security/advisories/GHSA-223g-f5mq-gw33
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.