AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-17T23:16:52.123Z and has not been modified since then. The vulnerability affects Mahara versions before 25.04.5 and 26.04.0, allowing crafted calls to recall backed-up content from another Text section. Organizations using Mahara should be aware of this vulnerability and take steps to patch or mitig [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-17T23:16:52.023Z and has not been modified since then. The vulnerability affects Mahara before 25.04.5 and 26.04.0, allowing artefacts to be accessible to others under certain circumstances when the file path to an artefact in a page is manipulated. This issue has a CVSS score of 9.1 and a severity [truncated]
Mahara before 25.04.5 and 26.04.0 is vulnerable to unauthorized access to internal accounts via Learning Tools Interoperability (LTI) under certain circumstances. This applies to LTI 1.1 and LTI 1.3 Advantage. The vulnerability allows attackers to bypass authentication and gain access to sensitive information. Organizations should review their LTI configurations and ensure that Mahara is patched to a secure version.