Executive brief
Mahara is an open-source ePortfolio system used by educational institutions to help students and staff create and share digital portfolios. This vulnerability allows attackers to gain unauthorized access to internal user accounts through the Learning Tools Interoperability (LTI) integration feature, potentially compromising sensitive student and staff data and enabling account takeover.
Technical details
This is an incorrect access control vulnerability in Mahara's LTI 1.1 and LTI 1.3 Advantage implementations that enables unauthorized access to internal accounts under certain circumstances. The vulnerability is remotely exploitable and requires no authentication. Attackers can leverage the flawed access control in the LTI integration to gain unauthorized access to user accounts, resulting in information disclosure and privilege escalation. The issue affects Mahara versions before 25.04.5 and 26.04.0; patches are available in Mahara 25.04.5+ and 26.04.1+.
Affected products
- Catalyst IT Mahara before 25.04.5 and 26.04.0
Timeline
- 2026-08-17: disclosed: CVE-2026-42163 publicly disclosed
- 2026-06-05: patched: Security maintenance releases Mahara 25.04.5 and 26.04.1 published