Vulnerability Description
OpenLearn is open-source educational forum software. Prior to commit 844b2a40a69d0c4911580fe501923f0b391313ab, when `safeMode` is enabled, unapproved forum posts are hidden from the public list, but the direct post-read procedure still returns the full post to anyone with the post UUID. Commit 844b2a40a69d0c4911580fe501923f0b391313ab fixes the issue.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Siemvk | Openlearn | < 2026-04-14 |
Related Weaknesses (CWE)
References
- https://github.com/siemvk/OpenLearn/commit/844b2a40a69d0c4911580fe501923f0b39131Patch
- https://github.com/siemvk/OpenLearn/security/advisories/GHSA-4rv3-hfh6-vqvmExploitVendor Advisory
- https://github.com/siemvk/OpenLearn/security/advisories/GHSA-4rv3-hfh6-vqvmExploitVendor Advisory
FAQ
What is CVE-2026-41243?
CVE-2026-41243 is a vulnerability with a CVSS score of 5.4 (MEDIUM). OpenLearn is open-source educational forum software. Prior to commit 844b2a40a69d0c4911580fe501923f0b391313ab, when `safeMode` is enabled, unapproved forum posts are hidden from the public list, but t...
How severe is CVE-2026-41243?
CVE-2026-41243 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-41243?
Check the references section above for vendor advisories and patch information. Affected products include: Siemvk Openlearn.