Unauthenticated Access Vulnerability in Open edX Platform by Open edX
CVE-2026-34736

5.3MEDIUM

Key Information:

Vendor

Openedx

Vendor
CVE Published:
2 April 2026

What is CVE-2026-34736?

The Open edX Platform is susceptible to an access control vulnerability that allows unauthenticated attackers to bypass the email verification system. This issue arises due to a combination of an OAuth2 password grant mechanism that issues tokens to inactive users and the exposure of the activation_key in the REST API response at /api/user/v1/accounts/. The flaw was identified and has been remedied in the ulmo release, offering enhanced security against unauthorized access.

Affected Version(s)

openedx-platform >= maple, < ulmo

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.