← Vulnerability feed

Vulnerability record · CVE-2026-31946 · published 30 March 2026

CVE-2026-31946: Frentix openolat improper authentication vulnerability

Frentix · Openolat

OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. From version 10.5.4 to before version 20.2.5, OpenOLAT's OpenID Connect implicit flow implementation does not verify JWT signatures. The JSONWebToken.parse() method silently discards the signature segment of the compact JWT (header.payload.signature), and the getAccessToken() methods in both OpenIdConnectApi and OpenIdConnectFullConfigurableApi only validate claim-level fields (issuer, audience, state, nonce) without any cryptographic signature verification against the Identity Provider's JWKS endpoint. This issue has been patched in version 20.2.5.

9.8 CVSS 3.1 Critical EPSS 0.33% · top 76.8% CWE-287 · Improper authenticationCWE-347 · Improper verification of cryptographic signature
9.8CVSS 3.1 base score
0.33%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. From version 10.5.4 to before version 20.2.5, OpenOLAT's OpenID Connect implicit flow implementation does not verify JWT signatures. The JSONWebToken.parse() method silently discards the signature segment of the compact JWT (header.payload.signature), and the getAccessToken() methods in both OpenIdConnectApi and OpenIdConnectFullConfigurableApi only validate claim-level fields (issuer, audience, state, nonce) without any cryptographic signature verification against the Identity Provider's JWKS endpoint. This issue has been patched in version 20.2.5.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-31946 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-28228Frentix openolat vulnerabilityOpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. Prior to versions 19.1.31, 20.1.18, an…EPSS 0.53%8.8CVE-2021-39181Frentix openolat xml injection vulnerabilityOpenOlat is a web-based learning management system (LMS). Prior to version 15.3.18, 15.5.3, and 16.0.0, using a prepared import XML file (e.g. a cour…EPSS 1.9%8.8CVE-2021-39180Frentix openolat path traversal vulnerabilityOpenOLAT is a web-based learning management system (LMS). A path traversal vulnerability exists in versions prior to 15.3.18, 15.5.3, and 16.0.0. Usi…EPSS 2.4%8.1CVE-2021-41242Frentix openolat relative path traversal vulnerabilityOpenOlat is a web-basedlearning management system. A path traversal vulnerability exists in OpenOlat prior to versions 15.5.12 and 16.0.5. By providi…EPSS 1.4%7.7CVE-2021-41152Frentix openolat path traversal vulnerabilityOpenOlat is a web-based e-learning platform for teaching, learning, assessment and communication, an LMS, a learning management system. In affected v…EPSS 1.2%7.5CVE-2024-28198Frentix openolat xml external entity (xxe) vulnerabilityOpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. By manually manipulating http requests…EPSS 0.43%5.4CVE-2024-25973Frentix openolat improper input validation vulnerabilityThe Frentix GmbH OpenOlat LMS is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities. An attacker with rights to create or edit gr…EPSS 0.56%5.4CVE-2024-25974Frentix openolat improper input validation vulnerabilityThe Frentix GmbH OpenOlat LMS is affected by stored a Cross-Site Scripting (XSS) vulnerability. It is possible to upload files within the Media Cente…EPSS 0.55%

Source: NIST National Vulnerability Database (record CVE-2026-31946), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.