Junglewise Threat Intelligence

CVE-2026-64961: ATutor authentication bypass in auto-login token validation

CVE-2026-64961 · Severity: info · CVSS 9.1 · Published 2026-08-20

Technologies: ATutor. Vendors: ATutor.

Executive brief

ATutor is a learning management system used by educational institutions to deliver online courses and manage student enrollment. An attacker who obtains a user's ID and registration date can bypass login authentication and gain immediate access to any account, including administrator accounts, without needing a password. This allows complete takeover of the platform and access to all course content and student data.

Technical details

The vulnerability exists in ATutor's auto-login token validation functionality. Although token validation checks are performed, the values required to validate tokens remain uninitialized in certain code paths. An unauthenticated attacker who can enumerate a user's identifier and registration timestamp can generate a valid authentication token and authenticate as that user, including administrators, without knowing or entering a password. The vulnerability affects ATutor 2.2.4 and likely other versions; the product is no longer actively maintained and fixes are unavailable. The attack requires no special privileges or user interaction—only network access to the ATutor application and knowledge of target user identifiers and registration dates.

Affected products

  • ATutor ATutor 2.2.4 and likely earlier versions

Timeline

  • 2026-08-20: disclosed
  • other: Product no longer actively supported; vulnerabilities remain unfixed

References

Related threats