PT-2026-30921 · Unknown · Polarlearn
Jvr2022
·
Published
2026-04-07
·
Updated
2026-04-07
·
CVE-2026-35610
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PolarLearn versions prior to 0-PRERELEASE-15
Description
PolarLearn is a learning program affected by a privilege-escalation issue. An inverted admin check in the
account-management module allowed authenticated non-admin users to execute the setCustomPassword(userId, password) and deleteUser(userId) actions, while legitimate administrators were blocked. The issue stems from an incorrect conditional statement that reverses the intended access control logic.Recommendations
Update to version 0-PRERELEASE-15 or later.
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Polarlearn