CVE-2026-42163: Mahara Mahara vulnerability
Published Aug 17, 2026
·Updated
Mahara before 25.04.5 and 26.04.0 is vulnerable to unauthorized access to internal accounts via Learning Tools Interoperability (LTI) under certain circumstances. This applies to LTI 1.1 and LTI 1.3 Advantage.
Affected Software
2 affected components
Mahara Mahara>25.04.4<=25.04.5
Mahara Mahara>25.04.5<26.04.0
Event History
Aug 17, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:17 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2026-42163?
CVE-2026-42163 has a risk rating of 60, indicating a moderate level of severity.
2
How do I fix CVE-2026-42163?
To address CVE-2026-42163, you should update Mahara to version 25.04.5 or 26.04.0 or later.
3
What systems are affected by CVE-2026-42163?
CVE-2026-42163 affects Mahara versions prior to 25.04.5 and 26.04.0.
4
What type of vulnerability is CVE-2026-42163?
CVE-2026-42163 is a vulnerability that allows unauthorized access to internal accounts through Learning Tools Interoperability (LTI).
5
Which LTI versions are impacted by CVE-2026-42163?
CVE-2026-42163 impacts LTI 1.1 and LTI 1.3 Advantage implementations.