PatchSiren

Mahara CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Mahara CVE published 2026-08-17

CVE-2026-42164

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-17T23:16:52.123Z and has not been modified since then. The vulnerability affects Mahara versions before 25.04.5 and 26.04.0, allowing crafted calls to recall backed-up content from another Text section. Organizations using Mahara should be aware of this vulnerability and take steps to patch or mitig [truncated]

CRITICAL Mahara CVE published 2026-08-17

CVE-2026-42162

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-17T23:16:52.023Z and has not been modified since then. The vulnerability affects Mahara before 25.04.5 and 26.04.0, allowing artefacts to be accessible to others under certain circumstances when the file path to an artefact in a page is manipulated. This issue has a CVSS score of 9.1 and a severity [truncated]

CRITICAL Mahara CVE published 2026-08-17

CVE-2026-42163

Mahara before 25.04.5 and 26.04.0 is vulnerable to unauthorized access to internal accounts via Learning Tools Interoperability (LTI) under certain circumstances. This applies to LTI 1.1 and LTI 1.3 Advantage. The vulnerability allows attackers to bypass authentication and gain access to sensitive information. Organizations should review their LTI configurations and ensure that Mahara is patched to a secure version.