<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Enocta Platform (&lt;= 2026-09-28) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/enocta-platform--2026-09-28/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 28 Sep 2026 14:15:14 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/enocta-platform--2026-09-28/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authorization Bypass in Enocta Platform (CVE-2026-82323)</title><link>https://feed.craftedsignal.io/briefs/2026-09-28-cve-2026-82323/</link><pubDate>Mon, 28 Sep 2026 14:15:14 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-28-cve-2026-82323/</guid><description>CVE-2026-82323 is an authorization bypass vulnerability in the Enocta Platform that allows attackers to manipulate user-controlled keys to escalate privileges and hijack trusted user sessions.</description><content:encoded><![CDATA[<p>CVE-2026-82323 describes a critical authorization bypass vulnerability affecting all versions of the Enocta Platform up to and including the release dated September 28, 2026. The vulnerability stems from improper validation of user-controlled keys used within the platform's authentication and session management workflows. By manipulating these keys, an unauthenticated or low-privileged attacker can perform an exploitation of trusted identifiers, effectively masquerading as other users or elevating their own privileges to administrative status. This flaw poses a significant risk to organizational data integrity and user privacy within the learning management environment, as it facilitates full account takeover without requiring knowledge of target credentials.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows unauthorized actors to gain access to the Enocta Platform as arbitrary users, including administrators. This can lead to the exfiltration of sensitive training data, manipulation of user progress records, and unauthorized changes to system configurations. Given the platform's role in educational technology, the impact includes potential compromise of personally identifiable information (PII) for all registered users of the affected systems.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Immediately update the Enocta Platform to the latest version as provided by the vendor to remediate CVE-2026-82323.</li>
<li>Review application access logs for unusual patterns of session ID usage or anomalous identity header values that deviate from expected standard platform behavior.</li>
<li>Audit administrative role assignments to identify unauthorized privilege escalations occurring during the period of exposure.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>identity-management</category><category>cve-2026-82323</category></item></channel></rss>