PT-2026-23217 · Themeum · Tutor Lms

M3Ez

+1

·

Published

2026-03-05

·

Updated

2026-03-07

·

CVE-2026-23799

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Themeum Tutor LMS versions through 3.9.5
Description A missing authorization flaw exists in Themeum Tutor LMS, allowing exploitation of incorrectly configured access control security levels. The issue allows unauthorized access.
Recommendations Update Themeum Tutor LMS to a version later than 3.9.5.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-23799

Affected Products

Tutor Lms