PT-2026-84818 · Unknown · Open Edx Lms

CVE-2026-53636

·

Published

2026-05-11

·

Updated

2026-09-02

CVSS v2.0

7.1

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Open edX LMS versions prior to commit 3a5ac85
Description The LTI (Learning Tools Interoperability) Provider implementation contains a flaw where the validate timestamp and nonce() function in lms/djangoapps/lti provider/signature validator.py fails to validate OAuth nonces or timestamps. This allows an attacker to capture a valid LTI launch request and replay it indefinitely without detection.
Recommendations Update to the version containing commit 3a5ac85.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-14041
CVE-2026-53636
GHSA-6GM5-C49G-P3H9

Affected Products

Open Edx Lms