Executive brief
Open edX is an open-source platform used to host and deliver online courses. A security flaw in the platform's SAML identity provider integration allows administrative users to force the server to make unauthorized requests to internal systems. This could allow an attacker to steal sensitive cloud credentials, scan private internal networks, or access internal services not intended for public exposure, potentially leading to a full compromise of the hosting environment.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in the `sync_provider_data` endpoint within the `SAMLProviderDataViewSet`. The `metadata_url` POST parameter is passed directly to `requests.get()` in the `fetch_metadata_xml()` function without validation of the URL scheme, IP address, or destination. An authenticated attacker with Enterprise Admin privileges can exploit this to perform internal network scanning or access cloud instance metadata services (e.g., AWS 169.254.169.254). In cloud environments, this can be escalated to Remote Code Execution (RCE) by stealing IAM credentials from the metadata service. The vulnerability has been addressed in commits 6fda1f120ff5a590d120ae1180185525f399c6d0 and 70a56246dd9c9df57c596e64bdd8a11b1d9da054.
Affected products
- Open edX Open edX Platform All versions containing SAMLProviderDataViewSet.sync_provider_data
Timeline
- 2026-04-24: advisory: GitHub Security Advisory published
- 2026-05-11: disclosed: CVE-2026-42858 published to NVD