PT-2026-6202 · Unknown · Open Eclass

Stolichnayer

·

Published

2026-02-03

·

Updated

2026-02-03

·

CVE-2026-24670

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Open eClass versions prior to 4.2
Description The Open eClass platform, previously known as GUnet eClass, is a course management system. A broken access control issue permits authenticated students to create new course units, a function typically reserved for users with greater privileges. The issue allows unauthorized creation of course units.
Recommendations Update to version 4.2 or later.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2026-24670
GHSA-4JF5-636R-HV9V

Affected Products

Open Eclass