PT-2026-30921 · Unknown · Polarlearn

·

CVE-2026-35610

·

Published

2026-04-07

·

Updated

2026-04-07

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PolarLearn versions prior to 0-PRERELEASE-15
Description PolarLearn is a learning program affected by a privilege-escalation issue. An inverted admin check in the account-management module allowed authenticated non-admin users to execute the setCustomPassword(userId, password) and deleteUser(userId) actions, while legitimate administrators were blocked. The issue stems from an incorrect conditional statement that reverses the intended access control logic.
Recommendations Update to version 0-PRERELEASE-15 or later.

Fix

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35610

Affected Products

Polarlearn