CVE-2026-24668: Open eClass Broken Access Control Allows Students to Add Content to Course Units
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a broken access control vulnerability allows authenticated students to add content to existing course units, an action normally restricted to higher-privileged roles. This issue has been patched in version 4.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24668?
CVE-2026-24668 is considered a high-severity vulnerability due to its potential to allow unauthorized content access and manipulation.
How do I fix CVE-2026-24668?
To mitigate CVE-2026-24668, upgrade Open eClass to version 4.2 or later to ensure all access controls are properly enforced.
Who is affected by CVE-2026-24668?
Authenticated students using Open eClass versions prior to 4.2 are affected by CVE-2026-24668.
What type of vulnerability is CVE-2026-24668?
CVE-2026-24668 is categorized as a broken access control vulnerability.
What can happen if CVE-2026-24668 is exploited?
Exploitation of CVE-2026-24668 can lead to unauthorized content being added to course units by students.