CVE-2026-24667

MEDIUM

Open eClass <4.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, failure to invalidate active user sessions after a password change allows existing session tokens to remain valid, potentially enabling unauthorized continued access to user accounts. This issue has been patched in version 4.2.

Scores

CVSS v3 5.0
EPSS 0.0005
EPSS Percentile 16.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-613
Status published
Products (1)
gunet/open_eclass_platform < 4.2
Published Feb 03, 2026
Tracked Since Feb 18, 2026