Junglewise Threat Intelligence

CVE-2026-34736: Open edX Platform authentication bypass via activation_key exposure

CVE-2026-34736 · Severity: medium · CVSS 5.3 · Published 2026-04-02

Technologies: Open edX Platform. Vendors: Open edX.

Executive brief

Open edX, a platform for delivering online learning, contains a flaw that allows new users to bypass email verification. By exploiting this, an attacker can create and activate accounts without having access to a valid email address, potentially leading to unauthorized access to course materials or platform features. This issue has been resolved in the 'ulmo' software release.

Technical details

An authentication bypass vulnerability exists in the Open edX Platform due to the exposure of the 'activation_key' field in the REST API response at /api/user/v1/accounts/. While the OAuth2 password grant intentionally issues tokens to inactive users, the inclusion of the activation key in the UserReadOnlySerializer allows an attacker to obtain the key without email access. An attacker can register an account, obtain an OAuth2 token, retrieve their own activation key via the API, and then programmatically trigger the activation endpoint. This issue affects versions from the 'maple' release up to 'ulmo', where it has been patched by removing the key from the API response.

Affected products

  • Open edX Open edX Platform >= maple, < ulmo

Timeline

  • 2026-03-30: advisory: GitHub Security Advisory published
  • 2026-04-02: disclosed: CVE published to NVD

References

Related threats