PT-2026-95023 · Scoold · Scoold

·

CVE-2026-54677

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Scoold versions prior to 1.69.0
Description Authenticated users who are not members of a private space can create content in questions belonging to that space. This occurs because the reply() function in QuestionController.java and the createAjax() function in CommentController.java fail to apply the canAccessSpace authorization check. When scoold.is default space public is set to false and private spaces are active, a user with a valid session and a known or enumerable question identifier can send requests to the endpoints 'POST /question/{id}' and 'POST /comment'. This allows unauthorized modification of private discussions and may trigger notifications that reveal metadata or the existence of private activity.
Recommendations Update to version 1.69.0.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54677
GHSA-H2P4-MM8G-WHXR

Affected Products

Scoold