CRITICAL 9.1 CVE-2026-42162 Published 17 Aug 2026

Mahara File Path Manipulation Leads to Unauthorized Artefact Access

Worried this affects one of your servers?

Mahara before 25.04.5 and 26.04.0 is vulnerable to unauthorized artefact access.

Under certain circumstances, artefacts can be accessed by other users when the file path to an artefact in a page is manipulated.

  • Affected versions: Mahara before 25.04.5 and 26.04.0
  • Impact: Artefacts may be accessible to others

Reference: CVE-2026-42162 on NVD

← Back to Security News