SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-54050

MEDIUM · CVSS 6.5 EPSS 0.31% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Sakai Collaboration and Learning Environment is vulnerable due to improper ownership verification in the DELETE /api/users/{userId}/profile/image and DELETE /api/users/{userId}/profile/pronunciation endpoints, allowing authenticated users to delete other users' profile images and pronunciation recordings. This could lead to significant disruption in workflows that depend on these identity artifacts, particularly affecting administrators and instructors. Organizations using versions 23.0 to 23.5 or 25.3 should prioritize upgrading to the patched versions to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-54050
Severity
MEDIUM
CVSS
6.5
EPSS
0.31%

Original NVD Description

Sakai is a Collaboration and Learning Environment (CLE). From 23.0 until 23.5 and 25.3, the DELETE /api/users/{userId}/profile/image endpoint allows an authenticated user to delete another user's profile image because ProfileController.removeProfileImage() passes the attacker-controlled userId to ProfileServiceImpl.removeProfileImage() without verifying ownership, and profileImageUploadedRepository.deleteById(userId) removes the selected row. The related DELETE /api/users/{userId}/profile/pronunciation endpoint also omits session validation and ownership checks before ProfileServiceImpl.removePronunciationRecording() deletes the target user's recording. The upload path is not affected because it already verifies ownership, and superusers remain intentionally authorized to modify other profiles. Successful exploitation can repeatedly remove profile identity artifacts, including administrator and instructor images, and disrupt workflows that rely on those artifacts. This issue is fixed in versions 23.5, 25.3, and 26.0.