Junglewise Threat Intelligence

CVE-2026-64965: ATutor missing authorization check in test and question import

CVE-2026-64965 · Severity: info · Published 2026-08-20

Technologies: ATutor. Vendors: ATutor.

Executive brief

ATutor is a learning management system (LMS) used by educational institutions to deliver online courses and assessments. A vulnerability allows low-privileged students enrolled in a course to import tests and questions without proper authorization, potentially corrupting course content or inserting unauthorized assessment material that could affect course integrity and student grades.

Technical details

The vulnerability is a missing authorization check (CWE-862) in the backend import endpoints for tests and questions. Low-privileged authenticated users (e.g., students) can bypass authorization controls by sending direct requests to these endpoints, allowing unauthorized import operations within a course. The attack requires an authenticated account and course enrollment but does not require instructor/administrator privileges. ATutor 2.2.4 is confirmed vulnerable; other versions are unknown. The product is no longer actively maintained and no patch is available.

Affected products

  • ATutor ATutor 2.2.4

Timeline

  • 2026-08-20: disclosed

References

Related threats