216.73.217.22

CVE-2026-25885

· Published 09/02/2026 22:16 · Modified 10/02/2026 15:22

Labels: CVE-2026-25885 2026-02-09CVE-2026-25885CWE-285[email protected]

Essential information

Published
09/02/2026 22:16
Modified
10/02/2026 15:22
Author
Creator
CVSS
10.0 CRITICAL (v3) 10.0 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

PolarLearn is a free and open-source learning program. In 0-PRERELEASE-16 and earlier, the group chat WebSocket at wss://polarlearn.nl/api/v1/ws can be used without logging in. An unauthenticated client can subscribe to any group chat by providing a group UUID, and can also send messages to any group. The server accepts the message and stores it in the group’s chatContent, so this is not just a visual spam issue.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
polarlearn / polarlearn cpe:2.3:a:polarlearn:polarlearn:0-PRERELEASE-16:*:*:*:*:*:*:*

References