CVE-2026-24670: Open eClass Has Broken Access Control in Course Units Module Allows Students to Create Units
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a broken access control vulnerability allows authenticated students to create new course units, an action normally restricted to higher-privileged roles. This issue has been patched in version 4.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24670?
CVE-2026-24670 is classified as a moderate vulnerability due to its impact on access control.
How do I fix CVE-2026-24670?
To fix CVE-2026-24670, upgrade to Open eClass version 4.2 or later.
Who is affected by CVE-2026-24670?
Authenticated users, specifically students, are affected by CVE-2026-24670 as it allows them to create unauthorized course units.
What type of vulnerability is CVE-2026-24670?
CVE-2026-24670 is a broken access control vulnerability.
What is the impact of CVE-2026-24670 on Open eClass?
CVE-2026-24670 allows authenticated students to improperly create new course units, potentially disrupting course management.