CVE-2026-31946 identifies a critical vulnerability in OpenOlat versions 10.5.4 through 20.2.4, where the OpenID Connect implicit flow implementation fails to verify JSON Web Token (JWT) signatures. Rated 9.8 Critical on CVSS, this flaw allows unauthenticated remote attackers to bypass authentication due to the absence of cryptographic signature validation, leading to high impacts on confidentiality, integrity, and availability. While no public exploits or active exploitation have been observed, the vulnerability has garnered limited community discussion. Organizations utilizing affected OpenOlat versions should upgrade to version 20.2.5 or newer to remediate this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.5.4, < 20.2.5CPE matchmatch criteria | cpe:2.3:a:frentix:openolat:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.