← Vulnerability feed

Vulnerability record · CVE-2026-28228 · published 30 March 2026

CVE-2026-28228: Frentix openolat vulnerability

Frentix · Openolat

OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. Prior to versions 19.1.31, 20.1.18, and 20.2.5, an authenticated user with the Author role can inject Velocity directives into a reminder email template. When the reminder is processed (either triggered manually or via the daily cron job), the injected directives are evaluated server-side. By chaining Velocity's #set directive with Java reflection, an attacker can instantiate arbitrary Java classes such as java.lang.ProcessBuilder and execute operating system commands with the privileges of the Tomcat process (typically root in containerized deployments). This issue has been patched in versions 19.1.31, 20.1.18, and 20.2.5.

8.8 CVSS 3.1 High EPSS 0.53% · top 57.5% CWE-1336 · CWE-1336
8.8CVSS 3.1 base score
0.53%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. Prior to versions 19.1.31, 20.1.18, and 20.2.5, an authenticated user with the Author role can inject Velocity directives into a reminder email template. When the reminder is processed (either triggered manually or via the daily cron job), the injected directives are evaluated server-side. By chaining Velocity's #set directive with Java reflection, an attacker can instantiate arbitrary Java classes such as java.lang.ProcessBuilder and execute operating system commands with the privileges of the Tomcat process (typically root in containerized deployments). This issue has been patched in versions 19.1.31, 20.1.18, and 20.2.5.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-28228 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-31946Frentix openolat improper authentication vulnerabilityOpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. From version 10.5.4 to before version …EPSS 0.33%8.8CVE-2021-39181Frentix openolat xml injection vulnerabilityOpenOlat is a web-based learning management system (LMS). Prior to version 15.3.18, 15.5.3, and 16.0.0, using a prepared import XML file (e.g. a cour…EPSS 1.9%8.8CVE-2021-39180Frentix openolat path traversal vulnerabilityOpenOLAT is a web-based learning management system (LMS). A path traversal vulnerability exists in versions prior to 15.3.18, 15.5.3, and 16.0.0. Usi…EPSS 2.4%8.1CVE-2021-41242Frentix openolat relative path traversal vulnerabilityOpenOlat is a web-basedlearning management system. A path traversal vulnerability exists in OpenOlat prior to versions 15.5.12 and 16.0.5. By providi…EPSS 1.4%7.7CVE-2021-41152Frentix openolat path traversal vulnerabilityOpenOlat is a web-based e-learning platform for teaching, learning, assessment and communication, an LMS, a learning management system. In affected v…EPSS 1.2%7.5CVE-2024-28198Frentix openolat xml external entity (xxe) vulnerabilityOpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. By manually manipulating http requests…EPSS 0.43%5.4CVE-2024-25973Frentix openolat improper input validation vulnerabilityThe Frentix GmbH OpenOlat LMS is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities. An attacker with rights to create or edit gr…EPSS 0.56%5.4CVE-2024-25974Frentix openolat improper input validation vulnerabilityThe Frentix GmbH OpenOlat LMS is affected by stored a Cross-Site Scripting (XSS) vulnerability. It is possible to upload files within the Media Cente…EPSS 0.55%

Source: NIST National Vulnerability Database (record CVE-2026-28228), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.