Junglewise Threat Intelligence

CVE-2026-85210: Oppia AdminRoleHandler information disclosure

CVE-2026-85210 · Severity: medium · CVSS 4.3 · Published 2026-09-03

Executive brief

Oppia's admin role management endpoint was exposed to all registered users due to improper access control configuration. Attackers can enumerate privileged user accounts, their assigned roles, ban status, and managed topics without authorization, enabling reconnaissance for further attacks on administrator accounts.

Technical details

The AdminRoleHandler GET endpoint in core/controllers/admin.py is decorated with the open_access decorator, which permits any authenticated user to access privileged information. The vulnerability allows attackers to query the endpoint with filter_criterion parameters to retrieve usernames of accounts holding specific administrative roles, boolean flags indicating banned status, and managed topic identifiers. The root cause is insufficient access control enforcement on an administrative endpoint that should restrict access to system administrators only. No authentication bypass is required—only user registration is needed. Patches should remove the open_access decorator and replace it with appropriate admin-level access controls.

Affected products

  • Oppia Oppia 3.5.2 and earlier

Timeline

  • 2026-09-03: disclosed

References