CVE-2026-41588General(inducer / relate)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch inducer relate systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

RELATE is a web-based courseware package. Prior to commit 2f68e16, there is a timing attack vulnerability in course/auth.py — check_sign_in_key(). This issue has been patched via commit 2f68e16.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-208CWE-203

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • relate

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • General: 3 classified signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 4 mentions (2026-05-13); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
relate

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-05-08: 1Mentions · 2026-05-13: 4Mentions · 2026-05-26: 1Patch / Workaround · 2026-05-26: 1Technical Details · 2026-05-08: 1Technical Details · 2026-05-13: 2Technical Details · 2026-05-26: 105-0805-1305-26
Signal classification3 categories
General
350.0%
Disclosure
233.3%
Patch
116.7%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-081
Disclosure1
2026-05-134
Disclosure1General3
2026-05-261
Patch1
Full discourse6 posts
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-41588-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The provided text only contains a link to an advisory for CVE-2026-41588, with no further details on exploitation, patching, or technical specifics.

    0001030
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    References CVE: CVE-2026-41588 CVSS: 9 (3.1) — CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The note announces CVE-2026-41588 as a critical vulnerability with a CVSS score of 9.0, yet it provides no PoC, exploit, patch, or detailed technical description beyond the severity classification.

    1000032
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVE: CVE-2026-41588 CVSS: 9 (3.1) — CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory RELATE is a web-based courseware package.

    Post summary

    The text announces CVE-2026-41588 with a high severity rating but provides no details on exploitation, mitigation, or technical aspects.

    1000033
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CRITICAL: CVE-2026-41588 (CVSS 9) — multiple products. CVE: CVE-2026-41588 CVSS: 9 (3.1) — CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The passage specifies CVE-2026-41588, its CVSS score, severity, and status as a critical advisory, but offers no proof of concept, exploit details, patch information, or indication of active exploitation.

    1000036
    210 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 CRITICAL: CVE-2026-41588 (CVSS 9.0) Timing attack vulnerability in RELATE web-based courseware (course/auth[.]py). Allows remote exploitation with high impact on confidentiality, integrity & availability. Patch: commit 2f68e16 #CVE #Vulnerability #PatchNow https://t.co/XdrQ3z1fPf

    Post summary

    The tweet announces the critical CVE-2026-41588, a timing attack in RELATE web-based courseware, and directs users to a patch commit that resolves the issue.

    0000060
    30 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41588 RELATE is a web-based courseware package. Prior to commit 2f68e16, there is a timing attack vulnerability in course/auth.py — check_sign_in_key(). This issue has been… https://www.cve.org/CVERecord?id=CVE-2026-41588

    Post summary

    The text announces a timing‑attack vulnerability in the RELATE courseware package (course/auth.py) and links to the CVE record.

    0000036
    57.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appinducerrelate---

Explore more