CVE-2026-28228Disclosure(frentix / openolat)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch frentix openolat systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. Prior to versions 19.1.31, 20.1.18, and 20.2.5, an authenticated user with the Author role can inject Velocity directives into a reminder email template. When the reminder is processed (either triggered manually or via the daily cron job), the injected directives are evaluated server-side. By chaining Velocity's #set directive with Java reflection, an attacker can instantiate arbitrary Java classes such as java.lang.ProcessBuilder and execute operating system commands with the privileges of the Tomcat process (typically root in containerized deployments). This issue has been patched in versions 19.1.31, 20.1.18, and 20.2.5.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1336

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openolat

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-30); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
openolat

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-30: 3Mentions · 2026-03-31: 1Patch / Workaround · 2026-03-31: 1Technical Details · 2026-03-30: 3Technical Details · 2026-03-31: 103-3003-31
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-303
Disclosure3
2026-03-311
Patch1
Full discourse4 posts
  • CVE@CVEnew
    Patch

    CVE-2026-28228 OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. Prior to versions 19.1.31, 20.1.18, and 20.2.5, an auth… https://www.cve.org/CVERecord?id=CVE-2026-28228

    Post summary

    CVE-2026-28228 impacts older OpenOlat releases and is resolved in newer versions; no PoC, exploit, or active exploitation details are provided.

    00000112
    56.9K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-28228 - High OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. Prior to versions 19.1.31, 20.1.18, and 20.2.5, an authenticated user with the A... https://www.thehackerwire.com/vulnerability/CVE-2026-28228/ https://t.co/fXTGq26Mxo

    Post summary

    The post announces a high‑severity authenticated privilege escalation flaw in OpenOlat versions prior to 19.1.31, 20.1.18, and 20.2.5, urging users to update.

    0000061
    158 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-28228 - OpenOLAT: Server-Side Template Injection (SSTI) in Velocity templates allows Remote Code Execution Intel Report: https://ift.tt/JTByIrs

    Post summary

    This alert announces CVE-2026-28228 in OpenOLAT as an SSTI flaw allowing RCE, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    0000087
    280 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-28228: HIGH] OpenOlat e-learning platform prior to versions 19.1.31, 20.1.18, and 20.2.5 had an authenticated user vulnerability allowing injection of Velocity directives in reminder emails, potent...#cve,CVE-2026-28228,#cybersecurity https://cvefind.com/CVE-2026-28228

    Post summary

    The tweet discloses that OpenOlat e-learning platform versions prior to 19.1.31, 20.1.18, and 20.2.5 have an authenticated user vulnerability allowing Velocity directive injection in reminder emails, with CVE-2026-28228 rated as HIGH severity.

    0000045
    608 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfrentixopenolat---

Explore more