PatchSiren

oppia CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM oppia CVE published 2026-09-03

CVE-2026-85210

CVE-2026-85210 is a medium-severity vulnerability in Oppia's AdminRoleHandler GET endpoint. The endpoint is decorated with open_access, allowing any registered user to enumerate privileged accounts and roles without authorization. Attackers can query the endpoint with filter_criterion parameters to retrieve usernames holding specific roles, banned flags, and managed topic identifiers.