CVE-2026-41243 is an access control bypass vulnerability affecting OpenLearn, an open-source educational forum software. When the safeMode security feature is enabled, unapproved forum posts are excluded from public listings; however, the vulnerability allows any user with a post's UUID to directly access and read the full content of these restricted posts, effectively circumventing the intended moderation controls. The issue was patched in commit 844b2a40a69d0c4911580fe501923f0b391313ab. The vulnerability operates over the network with likely low attack complexity, requiring only knowledge of a post UUID rather than elevated privileges. While a formal CVSS score is not available, the FAUCET Risk Score of 36.0/100 suggests moderate concern, and the EPSS rating of 0.0004 indicates this vulnerability is not a widespread threat across the CVE landscape. There is no evidence of active exploitation in the wild, no public exploit code availability, and the vulnerability has not been added to the CISA Known Exploited Vulnerabilities catalog. Community attention remains minimal, and the vulnerability is classified as inactive on threat tracking lists. Organizations running affected versions of OpenLearn should prioritize updating to the patched commit while monitoring for suspicious direct post access attempts.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2026-04-14CPE matchmatch criteria | cpe:2.3:a:siemvk:openlearn:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.