CVE-2026-24665

GUnet · Open eClass

A high-severity vulnerability has been identified in the GUnet Open eClass platform, a course management system used for educational purposes.

Executive summary

The GUnet Open eClass platform is affected by a high-severity vulnerability that could compromise the integrity and security of the course management system.

Vulnerability

While the specific technical vector is not detailed in the summary, the high CVSS score of 8.7 suggests a significant flaw, likely involving improper input validation or an authentication bypass within the platform's core logic.

Business impact

A successful exploit could lead to the unauthorized access of student and instructor data, modification of course content, or full administrative takeover of the eClass instance. The CVSS score of 8.7 indicates a high risk to data confidentiality and institutional reputation.

Remediation

Immediate Action: Administrators should apply the latest security patches from the GUnet Open eClass development team immediately.

Proactive Monitoring: Review application logs for suspicious administrative logins or unauthorized changes to course materials and user permissions.

Compensating Controls: Deploy a Web Application Firewall (WAF) to filter malicious traffic and implement strict IP whitelisting for administrative access.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Immediate remediation is advised to protect sensitive academic data. Organizations should verify their current version of Open eClass and upgrade to the latest stable release to ensure all security patches are in place.