Vulnerability in Sakai Collaboration and Learning Environment Affects User Profile Management
CVE-2026-54050

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-54050?

In Sakai's Collaboration and Learning Environment, versions 23.0 through 23.5 and 25.3, a flaw exists in the API endpoints that manage user profile images and pronunciations. An authenticated user can exploit this vulnerability to delete another user's profile image without proper ownership verification. Particularly, the DELETE /api/users/{userId}/profile/image endpoint and the associated pronunciation deletion endpoint lack necessary session validation and ownership checks, enabling unauthorized removal of profile identity artifacts. This disruption can significantly affect user workflows that rely on these identity features, especially for administrative and instructional roles. The issue has been addressed in later versions 23.5, 25.3, and 26.0.

Affected Version(s)

sakai >= 23.0, < 23.5 < 23.0, 23.5

sakai >= 25.0, <= 25.2 <= 25.0, 25.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.