Unauthorized Access in Oppia's AdminRoleHandler Endpoint
CVE-2026-85210
5.3MEDIUM
What is CVE-2026-85210?
The AdminRoleHandler GET endpoint in Oppia is exposed with insufficient authorization controls, allowing any registered user to access sensitive information. Attackers can exploit this vulnerability by manipulating the filter_criterion parameters to list usernames associated with specific roles and obtain additional details such as banned status and managed topics, thereby compromising the security of privileged accounts.
Affected Version(s)
oppia 0 <= 3.5.2
