CVE-2026-85210: Oppia

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Oppia's AdminRoleHandler GET endpoint in core/controllers/admin.py is decorated with open_access, allowing any registered user to enumerate privileged accounts and roles. Attackers can query the endpoint with filter_criterion parameters to retrieve usernames holding specific roles, banned flags, and managed topic identifiers without authorization.

Affected products

  • Oppia Oppia: up to and including 3.5.2

Published 2026-09-03. Last modified 2026-10-08.