THREAT OPS › Threat News › [NVD] CVE-2026-85210 (MEDIUM 4.3) — Oppia's AdminRoleHandler GET endpoint in core/controllers/admin.py is decorated with open_access, allowing any registered user to enumerate privileged accounts and roles. Attackers can query the endpoint with filter_criterion parameters to retrieve usernames holding specific role
[NVD] CVE-2026-85210 (MEDIUM 4.3) — Oppia's AdminRoleHandler GET endpoint in core/controllers/admin.py is decorated with open_access, allowing any registered user to enumerate privileged accounts and roles. Attackers can query the endpoint with filter_criterion parameters to retrieve usernames holding specific role
CVE-2026-85210 CVSS: 4.3 MEDIUM Published: 2026-09-03T15:17:40.103
Oppia's AdminRoleHandler GET endpoint in core/controllers/admin.py is decorated with open_access, allowing any registered user to enumerate privileged accounts and roles. Attackers can query the endpoint with filter_criterion parameters to retrieve usernames holding specific roles, banned flags, and managed topic identifiers witho
Indicators of compromise
- CVE-2026-85210cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-85210