Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 20 Feb 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Polarlearn
Polarlearn polarlearn |
|
| CPEs | cpe:2.3:a:polarlearn:polarlearn:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Polarlearn
Polarlearn polarlearn |
|
| Metrics |
cvssV3_1
|
Tue, 10 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Feb 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Polarnl
Polarnl polarlearn |
|
| Vendors & Products |
Polarnl
Polarnl polarlearn |
Mon, 09 Feb 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PolarLearn is a free and open-source learning program. In 0-PRERELEASE-16 and earlier, the group chat WebSocket at wss://polarlearn.nl/api/v1/ws can be used without logging in. An unauthenticated client can subscribe to any group chat by providing a group UUID, and can also send messages to any group. The server accepts the message and stores it in the group’s chatContent, so this is not just a visual spam issue. | |
| Title | PolarLearn allows Unauthenticated WebSocket access allows subscribing to and posting in arbitrary group chats | |
| Weaknesses | CWE-285 CWE-306 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-10T15:58:03.240Z
Reserved: 2026-02-06T21:08:39.129Z
Link: CVE-2026-25885
Updated: 2026-02-10T15:39:33.292Z
Status : Analyzed
Published: 2026-02-09T22:16:03.583
Modified: 2026-02-20T20:47:36.330
Link: CVE-2026-25885
No data.
OpenCVE Enrichment
Updated: 2026-04-17T21:15:27Z