CVE-2026-24664

MEDIUM

Open eClass <4.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a username enumeration vulnerability allows unauthenticated attackers to identify valid user accounts by analyzing differences in the login response behavior. This issue has been patched in version 4.2.

Scores

CVSS v3 5.3
EPSS 0.0009
EPSS Percentile 24.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-204
Status published
Products (1)
gunet/open_eclass_platform < 4.2
Published Feb 03, 2026
Tracked Since Feb 18, 2026