PatchSiren

Erudika CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Erudika CVE published 2026-04-07

CVE-2026-39354

CVE-2026-39354 is an authenticated authorization flaw in Scoold, a Q&A and knowledge sharing platform for teams. Prior to version 1.66.2, a low-privilege user can overwrite another user's existing question by supplying the public ID of that question as the postId parameter in a POST /questions/ask request. This is possible because question IDs are exposed in normal question URLs. As a result, an attacker [truncated]