PatchSiren

polarnl CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL polarnl CVE published 2026-04-07

CVE-2026-39322

CVE-2026-39322 is a critical authentication bypass vulnerability in PolarLearn 0-PRERELEASE-15 and earlier. The vulnerability allows an attacker to create a valid session for banned accounts before verifying the supplied password, enabling account data access and authenticated actions as the banned user. This issue exists in the POST /api/v1/auth/sign-in endpoint. The CVSS score for this vulnerability is [truncated]