PT-2026-79012 · Atutor · Atutor

·

CVE-2026-64964

·

Published

2026-08-20

·

Updated

2026-08-20

CVSS v4.0

6.3

Medium

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ATutor version 2.2.4
Description The account confirmation functionality generates predictable email confirmation tokens because it uses insufficiently random values related to user registration. An attacker capable of predicting these values can guess valid activation tokens to activate an unconfirmed account without accessing the victim's email inbox.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-64964

Affected Products

Atutor