CVE-2026-42162

Critical severity, CVSS 9.1. EPSS: 0.5% chance of exploitation in the next 30 days.

Mahara before 25.04.5 and 26.04.0 is vulnerable to artefacts being accessible to others under certain circumstances when the file path to an artefact in a page is manipulated.

Published 2026-08-17. Last modified 2026-08-31.