CVE-2026-34832 is an authenticated authorization flaw in Scoold versions prior to 1.66.1, allowing any low-privilege, logged-in user to delete other users' feedback posts by submitting the post's ID. Rated Medium (CVSS 6.5), this vulnerability can be exploited remotely with low complexity and low privileges, resulting in a high impact on data integrity through unauthorized deletion. There is currently no evidence of active exploitation, nor is public exploit code available, and community discussion or media coverage remains minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.66.1CPE matchmatch criteria | cpe:2.3:a:erudika:scoold:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.