CVE-2026-31946CRITICAL 9.8EPSS p10.7%

CVE-2026-31946CVE-2026-31946

Description

OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. From version 10.5.4 to before version 20.2.5, OpenOLAT's OpenID Connect implicit flow implementation does not verify JWT signatures. The JSONWebToken.parse() method silently discards the signature segment of the compact JWT (header.payload.signature), and the getAccessToken() methods in both OpenIdConnectApi and OpenIdConnectFullConfigurableApi only validate claim-level fields (issuer, audience, state, nonce) without any cryptographic signature verification against the Identity Provider's JWKS endpoint. This issue has been patched in version 20.2.5.

Scoring

CVSS 3.19.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS0.21% probability of exploitation · percentile 10.7% · 2026-06-19T12:03:05Z
Published2026-03-30
Last modified2026-04-02

Underlying weaknesses· 2

CWE-287CWE-347

References

  1. https://github.com/OpenOLAT/OpenOLAT/security/advisories/GHSA-v8vp-x4q4-2vch

2

TypeTargetConfidenceTier
WeaknessImproper Authenticationcwe-2870%live
WeaknessImproper Verification of Cryptographic Signaturecwe-3470%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-28802
CVE
CVE-2026-9793
CVE
CVE-2025-9485
CVE
CVE-2026-28228
CVE
CVE-2026-48526
CVE
CVE-2026-30223
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.