CVE-2026-39354
Scoold has an Authenticated Arbitrary Question Overwrite via Client-Controlled postId in POST /questions/ask
Description
Scoold is a Q&A and a knowledge sharing platform for teams. Prior to 1.66.2, an authenticated authorization flaw in Scoold allows any logged-in, low-privilege user to overwrite another user's existing question by supplying that question's public ID as the postId parameter to POST /questions/ask. Because question IDs are exposed in normal question URLs, a low-privilege attacker can take a victim question ID from a public page and cause attacker-controlled content to be stored under that existing question object. This causes direct integrity loss of user-generated content and corrupts the integrity of the existing discussion thread. This vulnerability is fixed in 1.66.2.
INFO
Published Date :
April 7, 2026, 7:16 p.m.
Last Modified :
July 24, 2026, 9:10 p.m.
Remotely Exploit :
Yes !
Source :
[email protected]
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | |||||
| CVSS 3.1 | MEDIUM | [email protected] |
Solution
- Update Scoold to version 1.66.2 or newer.
- Verify that the authorization flaw is remediated.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-39354.
| URL | Resource |
|---|---|
| https://github.com/Erudika/scoold/security/advisories/GHSA-768r-cv9p-wrcm | Exploit Vendor Advisory |
| https://github.com/Erudika/scoold/security/advisories/GHSA-768r-cv9p-wrcm | Exploit Vendor Advisory |
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-39354 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-39354
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-39354 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2026-39354 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
CVE Translated by [email protected]
Jul. 24, 2026
Action Type Old Value New Value Added Translation Title: Scoold de Erudika, Description: Scoold es una plataforma de preguntas y respuestas y de intercambio de conocimientos para equipos. Antes de la versión 1.66.2, un fallo de autorización autenticado en Scoold permite a cualquier usuario con sesión iniciada y de bajo privilegio sobrescribir la pregunta existente de otro usuario proporcionando el ID público de esa pregunta como el parámetro postId a POST /questions/ask. Debido a que los ID de las preguntas están expuestos en las URL normales de las preguntas, un atacante de bajo privilegio puede tomar el ID de una pregunta de la víctima de una página pública y hacer que el contenido controlado por el atacante se almacene bajo ese objeto de pregunta existente. Esto causa una pérdida directa de integridad del contenido generado por el usuario y corrompe la integridad del hilo de discusión existente. Esta vulnerabilidad está corregida en la versión 1.66.2. -
CVE Modified by [email protected]
Jun. 17, 2026
Action Type Old Value New Value Added Affected [{'vendor': 'Erudika', 'product': 'scoold', 'versions': [{'status': 'affected', 'version': '< 1.66.2'}]}] -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Jun. 17, 2026
Action Type Old Value New Value Added SSVC {'id': 'CVE-2026-39354', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'poc'}, {'automatable': 'no'}, {'technicalImpact': 'partial'}], 'version': '2.0.3', 'timestamp': '2026-04-09T15:04:47.366387Z'} -
Initial Analysis by [email protected]
Apr. 10, 2026
Action Type Old Value New Value Added CPE Configuration OR *cpe:2.3:a:erudika:scoold:*:*:*:*:*:*:*:* versions up to (excluding) 1.66.2 Added Reference Type CISA-ADP: https://github.com/Erudika/scoold/security/advisories/GHSA-768r-cv9p-wrcm Types: Exploit, Vendor Advisory Added Reference Type GitHub, Inc.: https://github.com/Erudika/scoold/security/advisories/GHSA-768r-cv9p-wrcm Types: Exploit, Vendor Advisory -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Apr. 09, 2026
Action Type Old Value New Value Added Reference https://github.com/Erudika/scoold/security/advisories/GHSA-768r-cv9p-wrcm -
New CVE Received by [email protected]
Apr. 07, 2026
Action Type Old Value New Value Added Description Scoold is a Q&A and a knowledge sharing platform for teams. Prior to 1.66.2, an authenticated authorization flaw in Scoold allows any logged-in, low-privilege user to overwrite another user's existing question by supplying that question's public ID as the postId parameter to POST /questions/ask. Because question IDs are exposed in normal question URLs, a low-privilege attacker can take a victim question ID from a public page and cause attacker-controlled content to be stored under that existing question object. This causes direct integrity loss of user-generated content and corrupts the integrity of the existing discussion thread. This vulnerability is fixed in 1.66.2. Added CVSS V3.1 AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Added CWE CWE-639 Added Reference https://github.com/Erudika/scoold/security/advisories/GHSA-768r-cv9p-wrcm