CRITICAL
9.1 CVE-2026-42162 Published 17 Aug 2026
Mahara File Path Manipulation Leads to Unauthorized Artefact Access
Worried this affects one of your servers?
Mahara before 25.04.5 and 26.04.0 is vulnerable to unauthorized artefact access.
Under certain circumstances, artefacts can be accessed by other users when the file path to an artefact in a page is manipulated.
- Affected versions: Mahara before 25.04.5 and 26.04.0
- Impact: Artefacts may be accessible to others
Reference: CVE-2026-42162 on NVD
← Back to Security News