mediumVulnerability
CVE-2026-44720
### Overview A critical authentication vulnerability was identified in OpenLearnX that could allow unauthorized access to user accounts under specific conditions. The issue has been fixed. **Advisory**: https://github.com/th30d4y/OpenLearnX/security/advisories/GHSA-223g-f5mq-gw33
Properties
- ghsa_id
- GHSA-223g-f5mq-gw33
- severity
- medium
- summary
- OpenLearnX: Critical Authentication Bypass via JWT Signature Verification Disabled Leading to Account Takeover
- epss_score
- 0.00207
- cve_id
- CVE-2026-44720
- is_ghsa_only
- false
- ghsa_published
- 2026-05-13T01:39:04Z
- source_url
- https://github.com/advisories/GHSA-223g-f5mq-gw33
- epss_percentile
- 0.10955
- ghsa_updated
- 2026-05-13T01:39:05Z
Related Entities (6)
ENRICHED_BY (1)
→[Source]FIRST EPSS
VULNERABLE_TO (1)
←[Software]npm/openlearnx
AFFECTS (1)
→[Software]npm/openlearnx
HAS_WEAKNESS (2)
→[Weakness]Improper Authentication
→[Weakness]Improper Verification of Cryptographic Signature
REPORTED_BY (1)
→[Source]GitHub Advisory Database
Explore deeper with Ninja Signal's threat intelligence graph