Junglewise Threat Intelligence

CVE-2026-53635: Open edX Platform privilege escalation in course price setting

CVE-2026-53635 · Severity: high · CVSS 7.6 · Published 2026-09-02

Technologies: Open edX Platform. Vendors: Open edX.

Executive brief

Open edX Platform is a widely-used online learning management system that enables educators to create and deliver courses at scale. An authentication bypass vulnerability in the course pricing endpoint allowed any logged-in user—including learners with no instructor privileges—to alter the honor mode price and currency for any course on the platform, potentially impacting course enrollment, revenue, and institutional trust. The flaw was introduced when a legacy frontend interface was removed while leaving the backend endpoint unprotected.

Technical details

The vulnerability is a privilege escalation (CWE-269) in the set_course_mode_price() view function located at lms/djangoapps/instructor/views/instructor_dashboard.py. The endpoint was decorated only with @login_required and performed no course-level authorization checks, allowing any authenticated user to POST requests that overwrite course honor-mode pricing and currency settings. The attack requires only network access and valid authentication credentials (no elevated privileges); an attacker can modify pricing for any course without the platform detecting unauthorized administrative changes. The patch (commit 59bb6d6 / f25bbc4) adds an is_staff check, restricting the endpoint to Django staff users. This endpoint has no known frontend callers, suggesting it is an orphaned legacy API that was overlooked during refactoring.

Affected products

  • Open edX Open edX Platform prior to commit 59bb6d6

Timeline

  • 2026-09-02: disclosed: Vulnerability disclosed via CVE-2026-53635
  • 2026-09-02: patched: Fix applied via commit 59bb6d6 / f25bbc4 requiring is_staff authorization

References

Related threats