Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-54677— Scoold: Authenticated user can post replies and comments to private-space questions without space membership

Quick assessment

Affected
Erudika scoold
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Scoold 是一个面向团队的问答与知识分享平台。在 1.69.0 版本之前,非私有空间成员的已认证用户仍然可以在该空间的问题下创建内容。原因在于 中的 方法和 中的 方法未应用问题读取路径所使用的 权限检查。 当 设置为 且启用了私有空间时,拥有有效会话且知道或可以枚举出问题标识符的用户,可以向 和 发送请求,从而在用户无法查看的线程中存储回复和评论。这允许未经授权地修改私有讨论,并可能触发通知,从而泄露私有活动的存在或元数据。 该问题已在 1.69.0 版本中修复。

CVSS 6.5 · Medium EPSS 0.38% · P29

Possible ATT&CK Techniques 1 AI

T1079

Affected Version Matrix 1

VendorProduct Version RangeStatus
Erudika scoold < 1.69.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-54677

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Scoold: Authenticated user can post replies and comments to private-space questions without space membership
Source: CVE Program / CVE List V5
Vulnerability Description
Scoold is a Q&A and a knowledge sharing platform for teams. Prior to 1.69.0, authenticated users who are not members of a private space can create content in questions belonging to that space because src/main/java/com/erudika/scoold/controllers/QuestionController.java in QuestionController.reply() and src/main/java/com/erudika/scoold/controllers/CommentController.java in CommentController.createAjax() do not apply the canAccessSpace authorization check used by the question read path. With scoold.is_default_space_public set to false and private spaces in use, a user with a valid session and a known or enumerable question identifier can send requests to POST /question/{id} and POST /comment, causing replies and comments to be stored in a thread the user cannot read. This permits unauthorized modification of private discussions and can trigger notifications that reveal the existence or metadata of private activity. This issue is fixed in version 1.69.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Erudika scoold < 1.69.0 -

II. Public POCs for CVE-2026-54677

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-54677

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-54677 (1)

Vendor Advisories for CVE-2026-54677 (1)

Vendor Pages for CVE-2026-54677 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-54677

No comments yet


Leave a comment