Unauthorized Access Vulnerability in Open edX Platform by Open edX
CVE-2026-53635

7.6HIGH

Key Information:

Vendor

Openedx

Vendor
CVE Published:
2 September 2026

What is CVE-2026-53635?

The Open edX Platform, an established solution for creating and managing online learning, has a security issue wherein authenticated users can exploit an improperly secured endpoint. Specifically, the view function set_course_mode_price() lacks sufficient course-level permission checks, allowing any authenticated individual to modify the honor mode price and currency of courses without legitimate authority. This vulnerability arises from a leftover endpoint that remains accessible despite the removal of its associated frontend modal. It is crucial for users to address this issue by updating to a patched version post commit 59bb6d6 to safeguard course integrity and maintain trust within the learning environment.

Affected Version(s)

openedx-platform < 59bb6d669e4fdc24d96afb809e12119372d9e257

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.