CVE-2026-85210: Oppia through 3.5.2 Missing Authorization on AdminRoleHandler GET

Published Sep 3, 2026
·
Updated

Oppia's AdminRoleHandler GET endpoint in core/controllers/admin.py is decorated with openaccess, allowing any registered user to enumerate privileged accounts and roles. Attackers can query the endpoint with filtercriterion parameters to retrieve usernames holding specific roles, banned flags, and managed topic identifiers without authorization.

Affected Software

1 affected component
Oppia<=3.5.2

Event History

Sep 3, 2026
CVE Published
via MITRE·02:12 PM
Data Sourced
via MITRE·02:12 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any registered Oppia user can query the affected GET endpoint. No administrator privileges or user interaction are required.

2

What information could an attacker obtain?

An attacker can enumerate privileged accounts and roles, including usernames associated with specific roles, banned flags, and managed topic identifiers. The described impact is information disclosure; no integrity or availability impact is stated.

3

Is an unauthenticated deployment affected?

The endpoint is described as accessible to any registered user, so an attacker must first have a valid user account. The data does not state that unauthenticated users can exploit it.

4

How can I determine whether my instance is affected?

The issue affects Oppia through version 3.5.2. Review the AdminRoleHandler GET implementation in core/controllers/admin.py and verify whether it is decorated with open_access and permits registered users to retrieve role-filtered account information.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203