Access Control Weakness in OpenSlides Presentation System
CVE-2026-25519
8.1HIGH
What is CVE-2026-25519?
OpenSlides, a web-based presentation and assembly system, has a vulnerability affecting its local login feature for users synchronized through an external Identity Provider (IDP) using SAML. Prior to version 4.2.29, it was possible for these users to gain unauthorized local access by using their OpenSlides username and a trivial password, which was valid for all SAML-connected accounts. This issue has been addressed and patched in version 4.2.29, enhancing the security of user authentication in OpenSlides.
Affected Version(s)
OpenSlides < 4.2.29
