mediumVulnerability

CVE-2026-44720

### Overview A critical authentication vulnerability was identified in OpenLearnX that could allow unauthorized access to user accounts under specific conditions. The issue has been fixed. **Advisory**: https://github.com/th30d4y/OpenLearnX/security/advisories/GHSA-223g-f5mq-gw33

Properties

ghsa_id
GHSA-223g-f5mq-gw33
severity
medium
summary
OpenLearnX: Critical Authentication Bypass via JWT Signature Verification Disabled Leading to Account Takeover
epss_score
0.00207
cve_id
CVE-2026-44720
is_ghsa_only
false
ghsa_published
2026-05-13T01:39:04Z
source_url
https://github.com/advisories/GHSA-223g-f5mq-gw33
epss_percentile
0.10955
ghsa_updated
2026-05-13T01:39:05Z

Related Entities (6)

ENRICHED_BY (1)

[Source]FIRST EPSS

VULNERABLE_TO (1)

[Software]npm/openlearnx

AFFECTS (1)

[Software]npm/openlearnx

HAS_WEAKNESS (2)

[Weakness]Improper Authentication
[Weakness]Improper Verification of Cryptographic Signature

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-44720 — Ninja Signal Threat Intelligence | Ninja Signal