CVE-2026-39322 affects PolarLearn, a free and open-source learning platform, in version 0-PRERELEASE-15 and earlier. The vulnerability exists in the POST /api/v1/auth/sign-in endpoint, which creates valid user sessions for banned accounts before validating the supplied password, allowing attackers to gain unauthorized access to banned user accounts and perform authenticated actions across the platform. The vulnerability carries a CVSS score of 8.8 (HIGH) with a network-based attack vector requiring minimal complexity and low privilege escalation. An authenticated attacker can exploit this flaw to access sensitive account data, modify information, and perform actions with the privileges of a banned user account, resulting in high confidentiality, integrity, and availability impact. There is currently no evidence of active exploitation in the wild, and the vulnerability does not appear on the KEV or Hot List registers. The EPSS score of 0.0005 indicates very low probability of exploitation at this time, and community attention remains limited, though the FAUCET Risk Score of 51.0 suggests moderate overall risk requiring remediation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:polarlearn:polarlearn:-:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.