CVE-2026-42164
9.8Mahara · Mahara
An information disclosure vulnerability in the Mahara Text block functionality allows unauthorized users to recall sensitive backed-up content from other sections.
Executive summary
A critical information disclosure vulnerability in Mahara versions before 25.04.5 and 26.04.0 allows unauthorized access to sensitive content.
Vulnerability
The vulnerability exists within the Text block or section functionality. An attacker can craft a specific call to the application that causes the system to incorrectly retrieve and display backed-up content from a different Text section, leading to unauthorized information disclosure.
Business impact
The CVSS score of 9.8 reflects the high impact on data confidentiality. Even without active exploitation, the ability for an unauthenticated user to retrieve sensitive or private information from other users' sections constitutes a severe breach of privacy and a failure of access control mechanisms, which could lead to significant reputational and compliance consequences.
Remediation
Immediate Action: Upgrade to Mahara 25.04.5 or later, or 26.04.0 or later, to remediate this vulnerability.
Proactive Monitoring: Review access logs for unusual or repetitive requests directed at the Text block functionality or endpoints associated with content retrieval.
Compensating Controls: Until patching is complete, restrict public access to instances of Mahara that contain sensitive user data and ensure that all users are aware of the risk of storing highly sensitive information in Text blocks.
Exploitation status
Public Exploit Available: No confirmed public exploit available.
Analyst recommendation
Organizations should prioritize upgrading to the patched versions of Mahara to ensure the integrity and confidentiality of user data. While no exploit is currently observed, the nature of the vulnerability presents a significant risk to data privacy that warrants immediate administrative action.