CRITICAL
polarnl
CVE published 2026-04-07
CVE-2026-39322
CVE-2026-39322 is a critical authentication bypass vulnerability in PolarLearn 0-PRERELEASE-15 and earlier. The vulnerability allows an attacker to create a valid session for banned accounts before verifying the supplied password, enabling account data access and authenticated actions as the banned user. This issue exists in the POST /api/v1/auth/sign-in endpoint. The CVSS score for this vulnerability is [truncated]