Junglewise Threat Intelligence

CVE-2026-42860: Open edX Enterprise Service SSRF in sync_provider_data endpoint

CVE-2026-42860 · Severity: high · CVSS 8.5 · Published 2026-05-11

Vendors: PyPI, Open edX.

Executive brief

A vulnerability in the edx-enterprise library, used in Open edX learning platforms, allows administrative users to perform Server-Side Request Forgery (SSRF). By providing a malicious URL in the SAML configuration, an attacker can force the server to make requests to internal systems or cloud metadata services. This could lead to the theft of sensitive cloud credentials, internal network scanning, or unauthorized access to private internal APIs.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the `sync_provider_data` endpoint of the `SAMLProviderDataViewSet`. The root cause is the `fetch_metadata_xml` function in `saml_utils.py`, which uses `requests.get()` on a user-controlled URL without validating the protocol scheme, enforcing IP allowlists/blocklists (such as RFC 1918 or link-local addresses), or setting a request timeout. An authenticated attacker with the 'Enterprise Admin' role can modify the `metadata_source` field via a PATCH request and then trigger an outbound HTTP request from the server. This can be exploited to access cloud instance metadata services (e.g., AWS IMDS) to retrieve IAM credentials or to scan internal network services. The issue is fixed in version 7.0.5.

Affected products

  • Open edX edx-enterprise >= 7.0.2, <= 7.0.4

Timeline

  • 2026-04-24: disclosed
  • 2026-05-05: advisory
  • 2026-05-05: patched: Version 7.0.5 released

References