Junglewise Threat Intelligence

CVE-2026-53636: Open edX Platform LTI replay attack in nonce validation

CVE-2026-53636 · Severity: medium · CVSS 4.7 · Published 2026-09-02

Technologies: Open edX Platform. Vendors: Open edX.

Executive brief

Open edX is an online learning platform used by educational institutions to deliver and manage courses at scale. A vulnerability in its LTI (Learning Tools Interoperability) integration allows attackers to replay captured learning tool launch requests repeatedly, potentially granting unauthorized access to course content or allowing impersonation of legitimate users without the ability to detect the attack.

Technical details

The vulnerability exists in the validate_timestamp_and_nonce function within lms/djangoapps/lti_provider/signature_validator.py, which fails to properly validate OAuth nonces and timestamps. This is a replay attack vulnerability (CWE-115/CWE-613) in the LTI Provider implementation. An attacker who intercepts a valid LTI launch request can replay it multiple times without detection or restriction. The attack requires network access to capture an LTI launch request but does not require authentication as the attacker reuses a legitimately captured request. The vulnerability has been patched in commit 3a5ac85, which implements OAuth nonce replay protection.

Affected products

  • Open edX Open edX Platform Prior to commit 3a5ac85

Timeline

  • 2026-09-02: disclosed
  • 2026-09-02: patched: Patch applied via commit 3a5ac85

References

Related threats