Session Management Flaw in PolarLearn Affects Banned Users
CVE-2026-39322
9.2CRITICAL
What is CVE-2026-39322?
PolarLearn, a free and open-source learning platform, has a significant vulnerability where the application improperly manages user session creation. Specifically, in versions 0-PRERELEASE-15 and earlier, the application allows the creation of valid sessions for accounts that are banned. This occurs before verifying the supplied password. Consequently, a session is accepted across various authenticated API routes, permitting access to account information and the ability to perform actions as if the user were legitimately logged in, despite being banned.
Affected Version(s)
PolarLearn <= v0-PRERELEASE-15
