Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-53635— Open edX Platform: Insufficient Permission on set_course_mode_price()

Quick assessment

Affected
openedx openedx-platform
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Open edX 平台支持以任意规模进行在线学习的创建与交付。在提交 59bb6d6 之前,位于 第 430 行的视图函数 仅被 装饰器保护,且未执行任何课程级别的权限检查。任何已认证用户——包括没有任何课程角色的学习者账户——都可以通过发送单个 POST 请求来覆盖平台上任意课程的荣誉模式(honor mode)价格及货币。配套的前端模态框已在之前的清理工作中被移除,但 URL 路由和视图函数仍保持活跃,这使得该端点成为一个缺少保护的“孤儿”端点。该问题已通过提交 59bb6d6 修复。

CVSS 7.6 · High EPSS 0.05% · P17
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-53635

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Open edX Platform: Insufficient Permission on set_course_mode_price()
Source: CVE Program / CVE List V5
Vulnerability Description
Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 59bb6d6, the view function set_course_mode_price() at lms/djangoapps/instructor/views/instructor_dashboard.py:430 is decorated only with @login_required and performs no course-level permission check. Any authenticated user — including a learner account with zero course roles — can issue a single POST request to overwrite the honor mode price and currency of any course on the platform. The companion frontend modal was removed in a prior cleanup, but the URL route and view remain live, making this an unguarded orphan endpoint. This issue has been patched via commit 59bb6d6.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
openedx openedx-platform < 59bb6d669e4fdc24d96afb809e12119372d9e257 -

II. Public POCs for CVE-2026-53635

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-53635

登录查看更多情报信息。

Patches & Fixes for CVE-2026-53635 (3)

Vendor Advisories for CVE-2026-53635 (1)

Same Patch Batch · openedx · 2026-09-02 · 3 CVEs total

CVE-2026-55421 6.8 MEDIUM Open edX Platform: SSRF in Studio Video Download Endpoint
CVE-2026-53636 4.7 MEDIUM Open edX LTI OAuth Replay Attack

IV. Related Vulnerabilities

V. Comments for CVE-2026-53635

No comments yet


Leave a comment