CVE-2026-41243
OpenLearn's pending forum posts remain publicly readable by direct ID when moderation mode is enabled
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
OpenLearn is open-source educational forum software. Prior to commit 844b2a40a69d0c4911580fe501923f0b391313ab, when `safeMode` is enabled, unapproved forum posts are hidden from the public list, but the direct post-read procedure still returns the full post to anyone with the post UUID. Commit 844b2a40a69d0c4911580fe501923f0b391313ab fixes the issue.
| CWE | CWE-284 |
| Vendor | siemvk |
| Product | openlearn |
| Published | Apr 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for siemvk openlearn
Be the first to know when new unknown vulnerabilities affecting siemvk openlearn are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
siemvk / OpenLearn
< 844b2a40a69d0c4911580fe501923f0b391313ab