Authentication Bypass Vulnerability in OpenFUN Richie LMS
CVE-2026-26717

Currently unrated

Key Information:

Vendor

OpenFUN

Vendor
CVE Published:
25 February 2026

Badges

👾 Exploit Exists🟡 Public PoC

What is CVE-2026-26717?

OpenFUN Richie LMS contains a vulnerability in its signature verification process due to the use of a non-constant time equality operator in the sync_course_run_from_request function. This flaw can enable remote attackers to exploit timing discrepancies to forge valid HMAC signatures, potentially allowing them to bypass authentication mechanisms. This vulnerability emphasizes the importance of constant-time algorithms in security-sensitive applications to mitigate timing attack possibilities.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.