๐Ÿ” CVE Alert

CVE-2026-41243

UNKNOWN 0.0

OpenLearn's pending forum posts remain publicly readable by direct ID when moderation mode is enabled

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

OpenLearn is open-source educational forum software. Prior to commit 844b2a40a69d0c4911580fe501923f0b391313ab, when `safeMode` is enabled, unapproved forum posts are hidden from the public list, but the direct post-read procedure still returns the full post to anyone with the post UUID. Commit 844b2a40a69d0c4911580fe501923f0b391313ab fixes the issue.

CWE CWE-284
Vendor siemvk
Product openlearn
Published Apr 23, 2026
Stay Ahead of the Next One

Get instant alerts for siemvk openlearn

Be the first to know when new unknown vulnerabilities affecting siemvk openlearn are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

siemvk / OpenLearn
< 844b2a40a69d0c4911580fe501923f0b391313ab

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/siemvk/OpenLearn/security/advisories/GHSA-4rv3-hfh6-vqvm github.com: https://github.com/siemvk/OpenLearn/commit/844b2a40a69d0c4911580fe501923f0b391313ab