← Back

CVE-2026-35610

nvd nist
Published: Apr 7, 2026Modified: Apr 16, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: security-advisories@github.com (Secondary)

Description

PolarLearn is a free and open-source learning program. In 0-PRERELEASE-14 and earlier, setCustomPassword(userId, password) and deleteUser(userId) in the account-management module used an inverted admin check. Because of the inverted condition, authenticated non-admin users were allowed to execute both actions, while real admins were rejected. This is a direct privilege-escalation issue in the application.

Affected (1)

1 product
Polarlearn
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions

References (1)

Source: security-advisories@github.com
ExploitVendor Advisory

Timeline

No history available yet.