Impact
Sakai is a Collaboration and Learning Environment (CLE). From 23.0 until 23.5 and 25.3, the DELETE /api/users/{userId}/profile/image endpoint allows an authenticated user to delete another user's profile image because ProfileController.removeProfileImage() passes the attacker-controlled userId to ProfileServiceImpl.removeProfileImage() without verifying ownership, and profileImageUploadedRepository.deleteById(userId) removes the selected row. The related DELETE /api/users/{userId}/profile/pronunciation endpoint also omits session validation and ownership checks before ProfileServiceImpl.removePronunciationRecording() deletes the target user's recording. The upload path is not affected because it already verifies ownership, and superusers remain intentionally authorized to modify other profiles. Successful exploitation can repeatedly remove profile identity artifacts, including administrator and instructor images, and disrupt workflows that rely on those artifacts. This issue is fixed in versions 23.5, 25.3, and 26.0.
Affected Systems
Sakai Collaboration and Learning Environment (CLE) versions 23.0 through 23.4 and 25.0 through 25.2 are affected. Fixed versions are 23.5, 25.3, and 26.0 and newer.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity risk. EPSS of <1% shows a very low probability that this vulnerability is currently being exploited. This issue is not listed in KEV. The attack vector is internal, requiring a legitimate DELETE request with another user’s identifier to trigger deletion. Because superusers are deliberately permitted to modify any profile, the flaw does not compromise system‑wide integrity beyond the target user’s profile image. The principal impact is the loss of user identity artifacts and the disruption of administrative or instructional workflows, rather than a critical system compromise.
OpenCVE Enrichment
Github GHSA