Authentication Bypass Vulnerability in OpenFUN Richie LMS
CVE-2026-26717
Key Information:
- Vendor
OpenFUN
- Status
- Vendor
- CVE Published:
- 25 February 2026
Badges
What is CVE-2026-26717?
OpenFUN Richie LMS contains a vulnerability in its signature verification process due to the use of a non-constant time equality operator in the sync_course_run_from_request function. This flaw can enable remote attackers to exploit timing discrepancies to forge valid HMAC signatures, potentially allowing them to bypass authentication mechanisms. This vulnerability emphasizes the importance of constant-time algorithms in security-sensitive applications to mitigate timing attack possibilities.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
