CVE-2026-42163
9.8Mahara · Mahara
Mahara is vulnerable to unauthorized internal account access via Learning Tools Interoperability (LTI) 1.1 and 1.3 due to improper request validation.
Executive summary
A critical vulnerability in Mahara allows unauthenticated remote attackers to gain unauthorized access to internal accounts through flawed Learning Tools Interoperability (LTI) processing.
Vulnerability
This vulnerability involves the improper validation of LTI 1.1 and 1.3 Advantage requests. An unauthenticated attacker can exploit these processing weaknesses to gain unauthorized access to internal user accounts within the Mahara platform.
Business impact
The CVSS score of 9.8 reflects the high potential for total system compromise and unauthorized data access. Exploitation of this flaw could lead to mass account takeover, exposure of sensitive educational or personal data, and severe loss of trust in the platform's security posture.
Remediation
Immediate Action: Upgrade Mahara to version 25.04.5, 26.04.0, or later versions immediately to address the LTI validation flaw.
Proactive Monitoring: Monitor authentication logs for unusual login patterns, particularly those associated with LTI integration points.
Compensating Controls: If immediate patching is not feasible, consider disabling LTI functionality temporarily to prevent unauthorized access attempts.
Exploitation status
Public Exploit Available: No (unknown)
Analyst recommendation
The criticality of this vulnerability necessitates an immediate update to the specified patched versions. Administrators should audit their LTI configurations to ensure that security controls are properly enforced while the update is being deployed.