VYPR
Moderate severityNVD Advisory· Published May 13, 2026· Updated May 13, 2026

OpenLearnX: Critical Authentication Bypass via JWT Signature Verification Disabled Leading to Account Takeover

CVE-2026-44720

Description

Overview

A critical authentication vulnerability was identified in OpenLearnX that could allow unauthorized access to user accounts under specific conditions. The issue has been fixed.

Advisory: https://github.com/th30d4y/OpenLearnX/security/advisories/GHSA-223g-f5mq-gw33

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
openlearnxnpm
< 2.0.42.0.4

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.