CyberRota Analysis
AI-GeneratedMahara versions prior to 25.04.5 and 26.04.0 are vulnerable in the Text block/section functionality, allowing an attacker to exploit a crafted call to retrieve backed-up content from another Text section. This could lead to unauthorized access to sensitive information. Organizations using affected versions should prioritize patching to mitigate potential data exposure risks.
CVE
CVE-2026-42164
Severity
CRITICAL
CVSS
9.8
EPSS
0.31%
Original NVD Description
Mahara before 25.04.5 and 26.04.0 is vulnerable in the Text block/section functionality when a call is crafted in a certain way that allows it to recall the backed-up content from another Text section.