CVE-2026-31946Disclosure(frentix / openolat)

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch frentix openolat systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. From version 10.5.4 to before version 20.2.5, OpenOLAT's OpenID Connect implicit flow implementation does not verify JWT signatures. The JSONWebToken.parse() method silently discards the signature segment of the compact JWT (header.payload.signature), and the getAccessToken() methods in both OpenIdConnectApi and OpenIdConnectFullConfigurableApi only validate claim-level fields (issuer, audience, state, nonce) without any cryptographic signature verification against the Identity Provider's JWKS endpoint. This issue has been patched in version 20.2.5.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-347

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openolat

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-30); latest day: 2
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
openolat

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-03-30: 3Mentions · 2026-03-31: 2Patch / Workaround · 2026-03-30: 1Technical Details · 2026-03-30: 2Technical Details · 2026-03-31: 103-3003-31
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-303
Disclosure2Patch1
2026-03-312
Disclosure2
Full discourse5 posts
  • CosmicBytez@CosmicBytez
    Disclosure

    Security Advisory: CVE-2026-31946: Critical JWT Signature Verification Bypass in OpenOlat E-Learning Platform https://labs.cosmicbytez.ca/security/cve-2026-31946 #Cybersecurity #InfoSec #CVE #PatchNow

    Post summary

    The advisory announces a critical JWT signature verification bypass in OpenOlat, informing users of the vulnerability and prompting timely patching.

    0000038
    1 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-31946 OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. From version 10.5.4 to before version 20.2.5, OpenOLAT'… https://www.cve.org/CVERecord?id=CVE-2026-31946

    Post summary

    The post announces CVE‑2026‑31946 as a vulnerability in OpenOLAT versions 10.5.4 to 20.2.5, but provides no PoC, exploit details, or patch information.

    00000120
    56.9K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-31946 - Critical OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. From version 10.5.4 to before version 20.2.5, OpenOLAT's OpenID Connect impl... https://www.thehackerwire.com/vulnerability/CVE-2026-31946/ https://t.co/OFNySdlB37

    Post summary

    The post announces the identification of CVE‑2026‑31946 in OpenOLAT, noting affected version ranges but providing no evidence of PoC, exploit availability, active exploitation, or mitigation steps.

    0000057
    158 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-31946: CRITICAL] OpenOlat, an e-learning platform, had a cyber security flaw in versions 10.5.4 to 20.2.4 with OpenID Connect not verifying JWT signatures. Update to version 20.2.5 to fix this.#cve,CVE-2026-31946,#cybersecurity https://cvefind.com/CVE-2026-31946

    Post summary

    OpenOlat’s e‑learning platform versions 10.5.4 to 20.2.4 suffered a critical flaw where OpenID Connect failed to verify JWT signatures; updating to version 20.2.5 resolves the issue.

    0000044
    608 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-31946: OpenOLAT: Aut... JWT.parse() silently drops signatures—craft any token, claim any identity, own the entire e-learning platform. #JWTFail #AuthBypass #OIDC. https://zerodaysignal.com/vulnerability/CVE-2026-31946 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces a new CVE (CVE‑2026‑31946) against OpenOLAT, describing a JWT signature bypass that could let anyone impersonate any identity. No PoC, exploit code, patch, or evidence of active exploitation is provided.

    0000081
    176 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfrentixopenolat---

Explore more