CVE-2026-31282 PUBLISHED

Assigner: mitre
Reserved: 09.03.2026 Published: 13.04.2026 Updated: 13.04.2026

Totara LMS v19.1.5 and before is vulnerable to Incorrect Access Control. The login page code can be manipulated to reveal the login form. An attacker can chain that with missing rate-limit on the login form to launch a brute force attack.

Product Status

Vendor n/a
Product n/a
Versions
  • Version n/a is affected

References

Problem Types

  • n/a text