MEDIUM
oppia
CVE published 2026-09-03
CVE-2026-85210
CVE-2026-85210 is a medium-severity vulnerability in Oppia's AdminRoleHandler GET endpoint. The endpoint is decorated with open_access, allowing any registered user to enumerate privileged accounts and roles without authorization. Attackers can query the endpoint with filter_criterion parameters to retrieve usernames holding specific roles, banned flags, and managed topic identifiers.