Vulnerability in Sakai Collaboration and Learning Environment Affects User Profile Management
CVE-2026-54050
What is CVE-2026-54050?
In Sakai's Collaboration and Learning Environment, versions 23.0 through 23.5 and 25.3, a flaw exists in the API endpoints that manage user profile images and pronunciations. An authenticated user can exploit this vulnerability to delete another user's profile image without proper ownership verification. Particularly, the DELETE /api/users/{userId}/profile/image endpoint and the associated pronunciation deletion endpoint lack necessary session validation and ownership checks, enabling unauthorized removal of profile identity artifacts. This disruption can significantly affect user workflows that rely on these identity features, especially for administrative and instructional roles. The issue has been addressed in later versions 23.5, 25.3, and 26.0.
Affected Version(s)
sakai >= 23.0, < 23.5 < 23.0, 23.5
sakai >= 25.0, <= 25.2 <= 25.0, 25.2
