LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-42163

Published
CVSS9.8
Severitycritical
WeaknessCWE-284
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

Mahara before 25.04.5 and 26.04.0 is vulnerable to unauthorized access to internal accounts via Learning Tools Interoperability (LTI) under certain circumstances. This applies to LTI 1.1 and LTI 1.3 Advantage.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-42163

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-42163.