Session Management Flaw in PolarLearn Affects Banned Users
CVE-2026-39322

9.2CRITICAL

Key Information:

Vendor

Polarnl

Vendor
CVE Published:
7 April 2026

What is CVE-2026-39322?

PolarLearn, a free and open-source learning platform, has a significant vulnerability where the application improperly manages user session creation. Specifically, in versions 0-PRERELEASE-15 and earlier, the application allows the creation of valid sessions for accounts that are banned. This occurs before verifying the supplied password. Consequently, a session is accepted across various authenticated API routes, permitting access to account information and the ability to perform actions as if the user were legitimately logged in, despite being banned.

Affected Version(s)

PolarLearn <= v0-PRERELEASE-15

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.