CVE-2026-24669: Open eClass Insecure Password Reset Token Reuse Enables Account Takeover
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, an insecure password reset mechanism allows local attackers to reuse a valid password reset token after it has already been used, enabling unauthorized password changes and potential account takeover. This issue has been patched in version 4.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24669?
CVE-2026-24669 is considered a high severity vulnerability due to the potential for account takeover.
How do I fix CVE-2026-24669?
To fix CVE-2026-24669, upgrade your Open eClass installation to version 4.2 or later.
Who is affected by CVE-2026-24669?
Users of Open eClass versions prior to 4.2 are affected by CVE-2026-24669.
What type of vulnerability is CVE-2026-24669?
CVE-2026-24669 is an insecure password reset token reuse vulnerability.
What can attackers do with CVE-2026-24669?
Attackers can exploit CVE-2026-24669 to reuse valid password reset tokens and take over user accounts.