Authentication Bypass Vulnerability in ATutor by ATutor Development Team
CVE-2026-64961
6.3MEDIUM
What is CVE-2026-64961?
ATutor has a serious vulnerability that allows unauthenticated attackers to bypass authentication mechanisms. Although a token validation mechanism is intended for the auto-login feature, it suffers from uninitialized values in specific code execution paths. An attacker with knowledge of a user's identifier and registration timestamp can exploit this flaw to generate a valid token, enabling impersonation of legitimate users, including administrators, without needing their passwords. The product is no longer actively supported, and only version 2.2.4 has been confirmed as vulnerable, suggesting similar untested versions may also be at risk.
Affected Version(s)
ATutor 2.2.4
References
CVSS V4
Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Michał Majchrowicz (AFINE Team)
Marcin Wyczechowski (AFINE Team)
