๐Ÿ” CVE Alert

CVE-2026-39322

HIGH 8.8

PolarLearn: Any password authenticates banned accounts and grants API access

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
13th

PolarLearn is a free and open-source learning program. In 0-PRERELEASE-15 and earlier, POST /api/v1/auth/sign-in creates a valid session for banned accounts before verifying the supplied password. That session is then accepted across authenticated /api routes, enabling account data access and authenticated actions as the banned user.

CWE CWE-287
Vendor polarnl
Product polarlearn
Published Apr 7, 2026
Last Updated Apr 9, 2026
Stay Ahead of the Next One

Get instant alerts for polarnl polarlearn

Be the first to know when new high vulnerabilities affecting polarnl polarlearn are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

polarnl / PolarLearn
<= v0-PRERELEASE-15

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/polarnl/PolarLearn/security/advisories/GHSA-9vx4-7ww7-4cf5