Evidence used
- No CISA KEV confirmation is currently recorded.
- A structured source references public exploit or proof-of-concept material.
- EPSS is 0.31% for the current model date.
BlackTreeCVE Intelligencesakaiproject · sakai
Official source article: GitHub GHSA-9284-FJC3-FMMJ ↗. Check the applicable product and release in the original source.
Medium technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.
These OSV and GitHub advisory ranges apply only to the named package and ecosystem. A listed fixed version is not a universal product patch or proof that an update is installed.
| Ecosystem and package | Affected range | First fixed version | Evidence |
|---|---|---|---|
| Mavenorg.sakaiproject.profile2:profile2-api | ECOSYSTEM: introduced 23.0; fixed 23.5 | 23.5 | OSV record ↗aggregator derived · 24 Aug 2026 |
| Mavenorg.sakaiproject.profile2:profile2-api | ECOSYSTEM: introduced 25.0; last affected 25.2 | Not stated | OSV record ↗aggregator derived · 24 Aug 2026 |
| Mavenorg.sakaiproject.profile2:profile2-impl | ECOSYSTEM: introduced 23.0; fixed 23.5 | 23.5 | OSV record ↗aggregator derived · 24 Aug 2026 |
| Mavenorg.sakaiproject.profile2:profile2-impl | ECOSYSTEM: introduced 25.0; last affected 25.2 | Not stated | OSV record ↗aggregator derived · 24 Aug 2026 |
| mavenorg.sakaiproject.profile2:profile2-api | >= 23.0, < 23.5 | 23.5 | GitHub advisory ↗upstream repository advisory · 24 Aug 2026 |
| mavenorg.sakaiproject.profile2:profile2-api | >= 25.0, <= 25.2 | Not stated | GitHub advisory ↗upstream repository advisory · 24 Aug 2026 |
| mavenorg.sakaiproject.profile2:profile2-impl | >= 23.0, < 23.5 | 23.5 | GitHub advisory ↗upstream repository advisory · 24 Aug 2026 |
| mavenorg.sakaiproject.profile2:profile2-impl | >= 25.0, <= 25.2 | Not stated | GitHub advisory ↗upstream repository advisory · 24 Aug 2026 |
Medium technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.
Fix not verifiedSakai is a Collaboration and Learning Environment (CLE). From 23.0 until 23.5 and 25.3, the DELETE /api/users/{userId}/profile/image endpoint allows an authenticated user to delete another user's profile image because ProfileController.removeProfileImage() passes the attacker-controlled userId to ProfileServiceImpl.removeProfileImage() without verifying ownership, and profileImageUploadedRepository.deleteById(userId) removes the selected row. The related DELETE /api/users/{userId}/profile/pronunciation endpoint also omits session validation and ownership checks before ProfileServiceImpl.removePronunciationRecording() deletes the target user's recording. The upload path is not affected because it already verifies ownership, and superusers remain intentionally authorized to modify other profiles. Successful exploitation can repeatedly remove profile identity artifacts, including administrator and instructor images, and disrupt workflows that rely on those artifacts. This issue is fixed in versions 23.5, 25.3, and 26.0.
Sakai is a Collaboration and Learning Environment (CLE). From 23.0 until 23.5 and 25.3, the DELETE /api/users/{userId}/profile/image endpoint allows an authenticated user to delete another user's profile image because ProfileController.removeProfileImage() passes the attacker-controlled userId to ProfileServiceImpl.removeProfileImage() without verifying ownership, and profileImageUploadedRepository.deleteById(userId) removes the selected row. The related DELETE /api/users/{userId}/profile/pronunciation endpoint also omits session validation and ownership checks before ProfileServiceImpl.removePronunciationRecording() deletes the target user's recording. The upload path is not affected because it already verifies ownership, and superusers remain intentionally authorized to modify other profiles. Successful exploitation can repeatedly remove profile identity artifacts, including administrator and instructor images, and disrupt workflows that rely on those artifacts. This issue is fixed in versions 23.5, 25.3, and 26.0.
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
An attacker operating through a network path may attempt exploitation with low privileges. If successful, the issue may cause the confidentiality, integrity or availability impact described by the vendor.
Sakai is a Collaboration and Learning Environment (CLE). From 23.0 until 23.5 and 25.3, the DELETE /api/users/{userId}/profile/image endpoint allows an authenticated user to delete another user's profile image because ProfileController.removeProfileImage() passes the attacker-controlled userId to ProfileServiceImpl.removeProfileImage() without verifying ownership, and profileImageUploadedRepository.deleteById(userId) removes the selected row. The related DELETE /api/users/{userId}/profile/pronunciation endpoint also omits session validation and ownership checks before ProfileServiceImpl.removePronunciationRecording() deletes the target user's recording. The upload path is not affected because it already verifies ownership, and superusers remain intentionally authorized to modify other profiles. Successful exploitation can repeatedly remove profile identity artifacts, including administrator and instructor images, and disrupt workflows that rely on those artifacts. This issue is fixed in versions 23.5, 25.3, and 26.0.
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
An attacker operating through a network path may attempt exploitation with low privileges. If successful, the issue may cause the confidentiality, integrity or availability impact described by the vendor.
CVSS severity, EPSS forecast probability, public exploit material and CISA-confirmed exploitation are separate signals.
No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.
CISA Vulnrichment records proof-of-concept exploitation in its SSVC data. BlackTree has not independently executed or validated exploit material.
CWE-639: Authorization Bypass Through User-Controlled Key. The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:NCommon Vulnerability Scoring System 3.1: the compact vector below is decoded into plain language.
Operational remediation based on structured source evidence.
Published 15 Sept 2026 · Last source change 15 Sept 2026, 19:00 UTC · CWE-639 · Authorization Bypass Through User-Controlled Key
Core structured fields are present and their contributing authorities are shown above.