CVE-2026-53636 | Open edX Platform LTI Provider signature_validator.py validate_timestamp_and_nonce authentication replay

SecurityVulns

A vulnerability described as critical has been identified in Open edX Platform. Affected by this issue is the function validate_timestamp_and_nonce of the file lms/djangoapps/lti_provider/signature_validator.py of the component LTI Provider. The manipulation results in authentication bypass by capture-replay.

This vulnerability is identified as CVE-2026-53636. The attack can be executed remotely. There is not any exploit available.

Applying a patch is advised to resolve this issue.VulDB Recent EntriesRead More