CVE@CVEnewPatch
CVE-2026-28228 impacts older OpenOlat releases and is resolved in newer versions; no PoC, exploit, or active exploitation details are provided.
The Hacker Wire@TheHackerWireDisclosure
The post announces a high‑severity authenticated privilege escalation flaw in OpenOlat versions prior to 19.1.31, 20.1.18, and 20.2.5, urging users to update.
CyberDudeBivash® | Global Cybersecurity Company@cyberbivashDisclosure
This alert announces CVE-2026-28228 in OpenOLAT as an SSTI flaw allowing RCE, but provides no PoC, exploit code, patch, or evidence of active exploitation.
CVEFind.com@CveFindComDisclosure
The tweet discloses that OpenOlat e-learning platform versions prior to 19.1.31, 20.1.18, and 20.2.5 have an authenticated user vulnerability allowing Velocity directive injection in reminder emails, with CVE-2026-28228 rated as HIGH severity.