CVE-2026-44720: OpenLearnX: Critical Authentication Bypass via JWT Signature Verification Disabled Leading to Account Takeover
(updated )
Overview
A critical authentication vulnerability was identified in OpenLearnX that could allow unauthorized access to user accounts under specific conditions. The issue has been fixed.
Advisory: https://github.com/th30d4y/OpenLearnX/security/advisories/GHSA-223g-f5mq-gw33
References
Code Behaviors & Features
Detect and mitigate CVE-2026-44720 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →