Unauthorized Access Vulnerability in Open edX Platform by Open edX
CVE-2026-53635
What is CVE-2026-53635?
The Open edX Platform, an established solution for creating and managing online learning, has a security issue wherein authenticated users can exploit an improperly secured endpoint. Specifically, the view function set_course_mode_price() lacks sufficient course-level permission checks, allowing any authenticated individual to modify the honor mode price and currency of courses without legitimate authority. This vulnerability arises from a leftover endpoint that remains accessible despite the removal of its associated frontend modal. It is crucial for users to address this issue by updating to a patched version post commit 59bb6d6 to safeguard course integrity and maintain trust within the learning environment.
Affected Version(s)
openedx-platform < 59bb6d669e4fdc24d96afb809e12119372d9e257
