CosmicBytez@CosmicBytezDisclosure
The advisory announces a critical JWT signature verification bypass in OpenOlat, informing users of the vulnerability and prompting timely patching.
CVE@CVEnewDisclosure
The post announces CVE‑2026‑31946 as a vulnerability in OpenOLAT versions 10.5.4 to 20.2.5, but provides no PoC, exploit details, or patch information.
The Hacker Wire@TheHackerWireDisclosure
The post announces the identification of CVE‑2026‑31946 in OpenOLAT, noting affected version ranges but providing no evidence of PoC, exploit availability, active exploitation, or mitigation steps.
CVEFind.com@CveFindComPatch
OpenOlat’s e‑learning platform versions 10.5.4 to 20.2.4 suffered a critical flaw where OpenID Connect failed to verify JWT signatures; updating to version 20.2.5 resolves the issue.
0day Signal@0dayPublishingDisclosure
The post announces a new CVE (CVE‑2026‑31946) against OpenOLAT, describing a JWT signature bypass that could let anyone impersonate any identity. No PoC, exploit code, patch, or evidence of active exploitation is provided.