Description
Scoold is a Q&A and a knowledge sharing platform for teams. Prior to 1.69.0, authenticated users who are not members of a private space can create content in questions belonging to that space because src/main/java/com/erudika/scoold/controllers/QuestionController.java in QuestionController.reply() and src/main/java/com/erudika/scoold/controllers/CommentController.java in CommentController.createAjax() do not apply the canAccessSpace authorization check used by the question read path. With scoold.is_default_space_public set to false and private spaces in use, a user with a valid session and a known or enumerable question identifier can send requests to POST /question/{id} and POST /comment, causing replies and comments to be stored in a thread the user cannot read. This permits unauthorized modification of private discussions and can trigger notifications that reveal the existence or metadata of private activity. This issue is fixed in version 1.69.0.
Published: 2026-09-17
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized content posting to private spaces
Action: Immediate patch
AI Analysis

Impact

Scoold allows authenticated users who are not members of a private space to post replies and comments on questions belonging to that space because the authorization check used by the read path is omitted from the reply and comment creation controllers. As a result, an attacker with a valid session can create or modify content in a private discussion that they cannot normally view, and the system may send notifications that expose the presence or details of those private interactions. This is an instance of an authorization bypass (CWE‑862).

Affected Systems

The vulnerability exists in all releases of Erudika Scoold prior to version 1.69.0. Users who run older builds with private spaces enabled (and scoold.is_default_space_public set to false) are susceptible.

Risk and Exploitability

The CVSS score of 6.5 indicates medium severity. The EPSS score of less than 1 % suggests a low likelihood of exploitation at this time, and the vulnerability is not listed in CISA’s KEV catalog. An attacker would need an authenticated session and the ID of a question within a private space, which can typically be enumerated or guessed. Once these conditions are met, the attacker can post arbitrary replies and comments that will be stored and potentially generate notifications revealing the existence or content of private discussions. Overall, the risk is moderate, with the primary concern being the inadvertent disclosure of private information.

Generated by OpenCVE AI on September 19, 2026 at 02:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Scoold version 1.69.0 or later, where the missing authorization check is restored.
  • If an upgrade is not immediately possible, configure the instance so that scoold.is_default_space_public is set to true and enforce strict access controls on all private spaces to prevent inadvertent exposure.
  • Verify that any custom or third‑party extensions to the Question or Comment controllers explicitly perform a canAccessSpace check before allowing content creation.

Generated by OpenCVE AI on September 19, 2026 at 02:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Erudika
Erudika scoold
Vendors & Products Erudika
Erudika scoold

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Scoold is a Q&A and a knowledge sharing platform for teams. Prior to 1.69.0, authenticated users who are not members of a private space can create content in questions belonging to that space because src/main/java/com/erudika/scoold/controllers/QuestionController.java in QuestionController.reply() and src/main/java/com/erudika/scoold/controllers/CommentController.java in CommentController.createAjax() do not apply the canAccessSpace authorization check used by the question read path. With scoold.is_default_space_public set to false and private spaces in use, a user with a valid session and a known or enumerable question identifier can send requests to POST /question/{id} and POST /comment, causing replies and comments to be stored in a thread the user cannot read. This permits unauthorized modification of private discussions and can trigger notifications that reveal the existence or metadata of private activity. This issue is fixed in version 1.69.0.
Title Scoold: Authenticated user can post replies and comments to private-space questions without space membership
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-24T20:55:22.845Z

Reserved: 2026-06-15T22:53:58.561Z

Link: CVE-2026-54677

cve-icon Vulnrichment

Updated: 2026-09-24T20:50:07.370Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T18:16:47.880

Modified: 2026-09-30T17:32:07.107

Link: CVE-2026-54677

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T02:45:16Z

Weaknesses