CVE-2026-24667: Open eClass's Active Sessions Not Invalidated After Password Change Allow Persistent Account Access
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, failure to invalidate active user sessions after a password change allows existing session tokens to remain valid, potentially enabling unauthorized continued access to user accounts. This issue has been patched in version 4.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24667?
CVE-2026-24667 has a moderate severity level due to the potential for unauthorized access resulting from persistent sessions.
How do I fix CVE-2026-24667?
To fix CVE-2026-24667, upgrade to Open eClass version 4.2 or newer to ensure active sessions are invalidated after a password change.
Which versions of Open eClass are affected by CVE-2026-24667?
CVE-2026-24667 affects all versions of Open eClass prior to version 4.2.
What type of vulnerability is CVE-2026-24667?
CVE-2026-24667 is an authentication vulnerability that allows persistent account access despite a password change.
What are the consequences of not addressing CVE-2026-24667?
Failure to address CVE-2026-24667 could lead to unauthorized access to user accounts, compromising sensitive information.