Executive brief
Scoold, a Q&A and knowledge-sharing platform, contains a vulnerability that allows an attacker to gain permanent administrator access. By exploiting a flaw in how the system validates security tokens, an attacker can modify the application's configuration file to add their own email address to the administrator list. While the change only takes effect after the application restarts, it provides a reliable way for an attacker to maintain control over the platform, potentially leading to the exposure of sensitive internal knowledge and unauthorized management of the system.
Technical details
Scoold prior to version 1.67.0 is vulnerable to a persistent privilege escalation flaw due to missing authentication/validation (CWE-306) in the `/api/config/set/admins` endpoint. An attacker can use a forged JWT (Bearer token) that lacks proper `jti` validation to authenticate as an administrator and modify the `scoold.admins` configuration value. The application writes this change directly to the configuration file. Although the `ADMINS` set is loaded into memory only at startup—meaning the exploit is not immediate—the attacker gains full administrative privileges once the Scoold service is restarted. This provides a durable persistence mechanism that survives session termination. The issue is fixed in version 1.67.0 by improving security checks in `ApiController`.
Affected products
- Erudika Scoold < 1.67.0
Timeline
- 2026-04-20: patched: Version 1.67.0 released
- 2026-05-08: disclosed: Public advisory published