OpenLearnX Authentication Bypass Vulnerability Allowing Account Takeover

Vulnerability

A critical authentication vulnerability has been identified in OpenLearnX versions prior to 2.0.3. This vulnerability could allow unauthorized access to user accounts under specific conditions, due to the JSON Web Token (JWT) signature verification being disabled, which could lead to an authentication bypass and account takeover.

Impact

Exploitation of this vulnerability could result in unauthorized access to user accounts, allowing an attacker to take over those accounts.

Remediation

Users can upgrade to OpenLearnX version 2.0.4 or later to address this vulnerability.

Added: May 28, 2026, 3:10 AM
Updated: May 28, 2026, 3:10 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.3
exploitability
7.4
remediation
0.0
relevance
9.6
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.