Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://github.com/saykino/CVE-2026-31283 |
|
| https://totara.com/ |
|
Wed, 29 Apr 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unrestricted Password Reset Causing Email Bombing in Totara LMS |
Fri, 24 Apr 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Totara LMS v19.1.5 and before, the forgot password API does not implement rate limiting for the target email address. which can be used for an Email Bombing attack. | In Totara LMS v19.1.5 and before, the forgot password API does not implement rate limiting for the target email address. which can be used for an Email Bombing attack. NOTE: the Supplier's position is that the pwresettime configuration defaults to 30 minutes, the pwresettime configuration is a hard control enforced via flag PWRESET_STATUS_ALREADYSENT, and no further password-reset email messages are sent if this flag is active for a specific email address. |
Wed, 15 Apr 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Missing Rate Limiting on Totara LMS Forgot Password API Allows Email Bombing |
Tue, 14 Apr 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 14 Apr 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Missing Rate Limiting on Totara LMS Forgot Password API Allows Email Bombing | |
| Weaknesses | CWE-770 |
Tue, 14 Apr 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Totara
Totara lms |
|
| Vendors & Products |
Totara
Totara lms |
Mon, 13 Apr 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Totara LMS v19.1.5 and before, the forgot password API does not implement rate limiting for the target email address. which can be used for an Email Bombing attack. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-24T07:32:30.441Z
Reserved: 2026-03-09T00:00:00.000Z
Link: CVE-2026-31283
Updated: 2026-04-14T15:41:49.753Z
Status : Deferred
Published: 2026-04-13T15:17:33.220
Modified: 2026-04-24T08:16:29.853
Link: CVE-2026-31283
No data.
OpenCVE Enrichment
Updated: 2026-04-29T02:00:27Z