Privilege Escalation in PolarLearn by Polar
CVE-2026-35610

8.8HIGH

Key Information:

Vendor

Polarnl

Vendor
CVE Published:
7 April 2026

What is CVE-2026-35610?

PolarLearn, an open-source learning program, contains a vulnerability in the account-management module where the setCustomPassword(userId, password) and deleteUser(userId) functions improperly check admin privileges. Due to an inverted condition, legitimate admin users are restricted from executing these actions, while authenticated non-admin users gain unauthorized access. This exploit poses a significant security risk, allowing non-admin users to escalate their privileges and manipulate user accounts, which could lead to data breaches or unauthorized actions within the application.

Affected Version(s)

PolarLearn <= 0-PRERELEASE-14

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.