Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-42163: Mahara LTI Access Risk - Unauthorized Account Access
CVE-2026-42163 · published 17 days ago
Summary
Mahara versions 25.04.5 and earlier, and 26.04.0, have a security issue that allows unauthorized access to internal accounts. This is a concern for institutions using Mahara for learning and collaboration, as it could lead to sensitive information being accessed by the wrong people. To mitigate this risk, update to the latest version of Mahara.
Original advisory text
Mahara before 25.04.5 and 26.04.0 is vulnerable to unauthorized access to internal accounts via Learning Tools Interoperability (LTI) under certain circumstances. This applies to LTI 1.1 and LTI 1....
Mahara before 25.04.5 and 26.04.0 is vulnerable to unauthorized access to internal accounts via Learning Tools Interoperability (LTI) under certain circumstances. This applies to LTI 1.1 and LTI 1.3 Advantage.
Severity
9.8
Critical
Exploitation
EPSS <1%
Type
CWE-284Improper Access Control
Timeline
Published17 Aug 2026
Updated30 Aug 2026
First seen17 Aug 2026
Monitor software like this
Free during beta