Predictable Token Generation Vulnerability in RELATE by Inducer
CVE-2026-41505

8.7HIGH

Key Information:

Vendor

Inducer

Status
Vendor
CVE Published:
7 May 2026

What is CVE-2026-41505?

RELATE, a web-based courseware package developed by Inducer, is susceptible to predictable token generation. This vulnerability exists in the functions make_sign_in_key() in auth.py and gen_ticket_code() in exam.py, potentially allowing unauthorized access. A fix has been implemented in commit 2f68e16 to address this security issue.

Affected Version(s)

relate < 2f68e16cd3b96d25c188c1aa3f7e13cdb15cdaeb

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.