{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aenocta_educational_technologiesenocta_platform/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:enocta_educational_technologies:enocta_platform:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-82323"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Enocta Platform (\u003c= 2026-09-28)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","identity-management","cve-2026-82323"],"_cs_type":"advisory","_cs_vendors":["Enocta Educational Technologies Inc."],"content_html":"\u003cp\u003eCVE-2026-82323 describes a critical authorization bypass vulnerability affecting all versions of the Enocta Platform up to and including the release dated September 28, 2026. The vulnerability stems from improper validation of user-controlled keys used within the platform's authentication and session management workflows. By manipulating these keys, an unauthenticated or low-privileged attacker can perform an exploitation of trusted identifiers, effectively masquerading as other users or elevating their own privileges to administrative status. This flaw poses a significant risk to organizational data integrity and user privacy within the learning management environment, as it facilitates full account takeover without requiring knowledge of target credentials.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthorized actors to gain access to the Enocta Platform as arbitrary users, including administrators. This can lead to the exfiltration of sensitive training data, manipulation of user progress records, and unauthorized changes to system configurations. Given the platform's role in educational technology, the impact includes potential compromise of personally identifiable information (PII) for all registered users of the affected systems.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the Enocta Platform to the latest version as provided by the vendor to remediate CVE-2026-82323.\u003c/li\u003e\n\u003cli\u003eReview application access logs for unusual patterns of session ID usage or anomalous identity header values that deviate from expected standard platform behavior.\u003c/li\u003e\n\u003cli\u003eAudit administrative role assignments to identify unauthorized privilege escalations occurring during the period of exposure.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-28T14:15:14Z","date_published":"2026-09-28T14:15:14Z","id":"https://feed.craftedsignal.io/briefs/2026-09-28-cve-2026-82323/","summary":"CVE-2026-82323 is an authorization bypass vulnerability in the Enocta Platform that allows attackers to manipulate user-controlled keys to escalate privileges and hijack trusted user sessions.","title":"Authorization Bypass in Enocta Platform (CVE-2026-82323)","url":"https://feed.craftedsignal.io/briefs/2026-09-28-cve-2026-82323/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:enocta_educational_technologies:enocta_platform:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}