Description
Mahara before 25.04.5 and 26.04.0 is vulnerable in the Text block/section functionality when a call is crafted in a certain way that allows it to recall the backed-up content from another Text section.
Published: 2026-08-17
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A crafted call within Mahara’s Text block or section functionality can trigger the recall of backed‑up content from a different Text section. This behaviour allows an attacker to read data that should be otherwise inaccessible, potentially exposing confidential or sensitive information stored in the system. The vulnerability represents an information disclosure flaw rather than a code execution or denial‑of‑service issue.

Affected Systems

Mahara versions prior to 25.04.5 and 26.04.0 are affected. The exploit targets the platform’s built‑in Text block/section feature and any instance that runs these unpatched releases.

Risk and Exploitability

No EPSS score is available and the vulnerability has not been listed in CISA’s KEV catalog, indicating no known widespread exploitation. The attack vector appears to be via a crafted request to the Text block interface, which may be accessible to authenticated users with sufficient permissions. Depending on user rights, the risk level varies, but the lack of exploitation data suggests a moderate risk unless the affected platform is publicly reachable and users can exercise the vulnerable functionality.

Generated by OpenCVE AI on August 18, 2026 at 00:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Mahara to version 25.04.5 or newer, or 26.04.0 or newer, to eliminate the vulnerability.
  • If an upgrade is not immediately possible, restrict or disable the Text block/section functionality for users until a patch can be applied.
  • After applying a fix, verify that old backups are properly cleaned or inaccessible to prevent accidental disclosure.
  • Monitor web and system logs for attempts to access backup content and alert on unauthorized access attempts.

Generated by OpenCVE AI on August 18, 2026 at 00:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Recall of Backed-up Content in Mahara Text Block
Weaknesses CWE-200

Mon, 17 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Mahara
Mahara mahara
Vendors & Products Mahara
Mahara mahara

Mon, 17 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Description Mahara before 25.04.5 and 26.04.0 is vulnerable in the Text block/section functionality when a call is crafted in a certain way that allows it to recall the backed-up content from another Text section.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-17T22:07:24.774Z

Reserved: 2026-04-24T00:00:00.000Z

Link: CVE-2026-42164

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-17T23:16:52.123

Modified: 2026-08-17T23:16:52.123

Link: CVE-2026-42164

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T00:15:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor