Authorization Bypass in Scoold for Unauthorized Content Creation
CVE-2026-54677

6.5MEDIUM

Key Information:

Vendor

Erudika

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-54677?

In versions of Scoold prior to 1.69.0, authenticated users could exploit a lack of necessary authorization checks, allowing them to create content within private spaces they do not belong to. Specifically, the issue arises in the QuestionController.reply() and CommentController.createAjax() functionalities where the canAccessSpace check is omitted. This flaw enables an authenticated user with knowledge of a private question’s identifier to submit replies and comments to it, thus modifying private discussions they are not authorized to engage with. Such actions could also send notifications that leak information about sensitive private activities within the platform.

Affected Version(s)

scoold < 1.69.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.