Summary
CVE-2026-42163 is a critical improper access control vulnerability (CWE-284) in Mahara, the open-source ePortfolio platform. It allows unauthorized access to internal user accounts through the Learning Tools Interoperability (LTI) integration under certain circumstances, affecting both LTI 1.1 and LTI 1.3 Advantage implementations. The issue carries a CVSS v3.1 base score of 9.8 (Critical) and can lead to information disclosure and privilege escalation without authentication or user interaction.
Technical details
- Root cause: Improper access control (CWE-284) within Mahara’s LTI authentication/integration handling, affecting both LTI 1.1 and LTI 1.3 Advantage implementations.
- Trigger conditions: Occurs "under certain circumstances" on sites that have LTI integration enabled; the vendor has not published further technical specifics of the trigger.
- Attack vector: Network-based (AV:N), low attack complexity, no privileges required, no user interaction required.
- Impact: Unauthorized access to internal user accounts, resulting in information disclosure and escalation of privileges.
Affected software
- Mahara before 25.04.7
- Mahara before 26.04.1
- (Vendor advisory references Mahara before 25.04.5 and 26.04.0 as the vulnerable baseline, with fixes released in 25.04.7 and 26.04.1)
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Upgrade to Mahara 25.04.7, 26.04.1, or later, as published on the official Mahara security announcement.
- If no patch can be applied immediately: The vendor has not published a workaround; organizations unable to patch should consider disabling or restricting LTI 1.1/1.3 integrations until the upgrade is applied, and closely monitor accounts accessible via LTI for suspicious activity.
- Organizations on older, no-longer-supported Mahara branches should upgrade to at least Mahara 25.04 to continue receiving security updates, per the vendor’s recommendation.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Meta tag
generator:Mahara(with optional version number following) - Response header
set-cookie:mahara=

