CVE-2026-25126 describes an improper input validation vulnerability in PolarLearn, an open-source learning program, affecting versions prior to 0-PRERELEASE-15. The vote API route (POST /api/v1/forum/vote) fails to validate the 'direction' value in the JSON body at runtime, allowing attackers to submit arbitrary strings. This bypasses business logic, as the system interprets any non-"up" or non-"null" value as a downvote, persisting invalid data. This vulnerability carries a CVSS score of 7.1 (HIGH), indicating a network-based attack with low attack complexity and no user interaction required. A successful exploit could lead to high integrity impact (manipulation of vote data) and low confidentiality impact, but no availability impact. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community discussion and media coverage, suggesting low public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:polarlearn:polarlearn:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.