Improper Verification of Cryptographic Signature in OpenOlat - CVE-2026-31946

 

Improper Verification of Cryptographic Signature in OpenOlat - CVE-2026-31946

Published: April 27, 2026


Vulnerability identifier: #VU128164
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-31946
CWE-ID: CWE-347
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication and obtain an authenticated session as any user.

The vulnerability exists due to improper verification of cryptographic signature in the OIDC implicit flow implementation when handling JWTs returned to the /oauthcallback endpoint. A remote attacker can construct and submit a forged JWT with an arbitrary sub claim to bypass authentication and obtain an authenticated session as any user.

Only installations with OIDC implicit flow enabled are vulnerable. The issue does not affect installations that do not use OAuth or that use only the authorization code flow.


Affected software

OpenOlat

How to mitigate CVE-2026-31946

Install security update from vendor's website.

OpenOlat - update to 20.2.5

External References

Related Security Bulletins