Access Control Weakness in OpenSlides Presentation System
CVE-2026-25519

8.1HIGH

Key Information:

Vendor

Openslides

Vendor
CVE Published:
4 February 2026

What is CVE-2026-25519?

OpenSlides, a web-based presentation and assembly system, has a vulnerability affecting its local login feature for users synchronized through an external Identity Provider (IDP) using SAML. Prior to version 4.2.29, it was possible for these users to gain unauthorized local access by using their OpenSlides username and a trivial password, which was valid for all SAML-connected accounts. This issue has been addressed and patched in version 4.2.29, enhancing the security of user authentication in OpenSlides.

Affected Version(s)

OpenSlides < 4.2.29

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.