CVE-2026-24773: Open eClass Unauthenticated IDOR Allows Access to Arbitrary User Files
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, an Insecure Direct Object Reference (IDOR) vulnerability allows unauthenticated remote attackers to access personal files of other users by directly requesting predictable user identifiers. This issue has been patched in version 4.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24773?
CVE-2026-24773 is classified as a high-severity vulnerability due to its potential for unauthorized access to sensitive user files.
How do I fix CVE-2026-24773?
To fix CVE-2026-24773, upgrade Open eClass to version 4.2 or later where this vulnerability has been addressed.
What type of vulnerability is CVE-2026-24773?
CVE-2026-24773 is an Insecure Direct Object Reference (IDOR) vulnerability that allows unauthorized access to user files.
Who is affected by CVE-2026-24773?
Users of Open eClass prior to version 4.2 are affected by CVE-2026-24773.
Can CVE-2026-24773 be exploited remotely?
Yes, CVE-2026-24773 can be exploited remotely by unauthenticated attackers.