CVE-2026-26717
MEDIUMRichie < 3.3.0 - Observable Timing Discrepancy in HMAC Signature Verification
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2026-26717. PoCs published by XiaomingX, Rickidevs.
AI-analyzed exploit summary This repository contains a functional SQL injection exploit for CVE-2025-10042, targeting WordPress Quiz Maker plugin versions <= 6.7.0.56. The exploit uses time-based blind SQLi to extract admin credentials and hashes.
Description
An issue in OpenFUN Richie (LMS) in src/richie/apps/courses/api.py. The application used the non-constant time == operator for HMAC signature verification in the sync_course_run_from_request function. This allows remote attackers to forge valid signatures and bypass authentication by measuring response time discrepancies
Exploits (2)
This repository contains a functional SQL injection exploit for CVE-2025-10042, targeting WordPress Quiz Maker plugin versions <= 6.7.0.56. The exploit uses time-based blind SQLi to extract admin credentials and hashes.
This repository provides a detailed technical analysis of CVE-2026-26717, a HMAC timing attack vulnerability in OpenFUN Richie LMS. It explains the root cause, impact, and fix, including code snippets and references to the fix commit.
References (3)
Scores
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N