Junglewise Threat Intelligence

CVE-2026-64969: ATutor IDOR in profile picture endpoints

CVE-2026-64969 · Severity: info · Published 2026-08-20

Technologies: ATutor. Vendors: ATutor.

Executive brief

ATutor is a learning management system that allows organizations to create and deliver online courses. The platform contains an insecure direct object reference (IDOR) vulnerability in its profile picture management feature that allows any authenticated student to permanently delete other users' profile pictures, including those of instructors and administrators. This could disrupt user identification and trust in the platform while causing operational friction for course participants.

Technical details

The vulnerability is a classic IDOR (CWE-639: Authorization bypass through User-Controlled key) affecting the profile album endpoint. An authenticated attacker can supply an arbitrary member_id in a POST request to delete profile pictures belonging to any other user without authorization checks. The attack requires only valid authentication as any user (including a student) and network access to the endpoint. An attacker can permanently remove profile pictures of other users, potentially including instructors and administrators. The product is no longer actively supported and the vulnerability has not been patched. Version 2.2.4 was confirmed vulnerable; other versions have not been tested but may be affected.

Affected products

  • ATutor ATutor 2.2.4 (confirmed vulnerable; other versions untested)

Timeline

  • 2026-08-20: disclosed

References

Related threats