Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 14 Apr 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Polarlearn
Polarlearn polarlearn |
|
| CPEs | cpe:2.3:a:polarlearn:polarlearn:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Polarlearn
Polarlearn polarlearn |
Thu, 09 Apr 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 08 Apr 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Polarnl
Polarnl polarlearn |
|
| Vendors & Products |
Polarnl
Polarnl polarlearn |
Tue, 07 Apr 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PolarLearn is a free and open-source learning program. In 0-PRERELEASE-15 and earlier, POST /api/v1/auth/sign-in creates a valid session for banned accounts before verifying the supplied password. That session is then accepted across authenticated /api routes, enabling account data access and authenticated actions as the banned user. | |
| Title | PolarLearn: Any password authenticates banned accounts and grants API access | |
| Weaknesses | CWE-287 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-09T16:16:51.970Z
Reserved: 2026-04-06T19:31:07.266Z
Link: CVE-2026-39322
Updated: 2026-04-09T16:16:11.808Z
Status : Analyzed
Published: 2026-04-07T20:16:28.773
Modified: 2026-04-14T18:44:29.327
Link: CVE-2026-39322
No data.
OpenCVE Enrichment
Updated: 2026-04-15T16:15:11Z