CVE Explorer
CVE-2026-42858
Open edX Platform enables the authoring and delivery of online learning at any scale. The sync_provider_data endpoint in SAMLProviderDataViewSet allows authenticated Enterprise Admin users to supply an arbitrary URL via the metadata_url POST parameter. This URL is passed directly to requests.get() in fetch_metadata_xml() without any URL validation, IP filtering, or scheme enforcement. An attacker with Enterprise Admin privileges can force the server to make HTTP requests to internal network serv
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"openedx-platform","vendor":"openedx","versions":[{"status":"affected","version":"< 6fda1f120ff5a590d120ae1180185525f399c6d0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:a56d6f6d6b4e0ea8b542cfdefb1449fe3b85210e5b72af6f1bed80385a0a8d9d · sha256:3bdadbcbf443196f… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":8.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:a56d6f6d6b4e0ea8b542cfdefb1449fe3b85210e5b72af6f1bed80385a0a8d9d · sha256:3bdadbcbf443196f… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-918","description":"CWE-918: Server-Side Request Forgery (SSRF)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:a56d6f6d6b4e0ea8b542cfdefb1449fe3b85210e5b72af6f1bed80385a0a8d9d · sha256:3bdadbcbf443196f… · /containers/cna/problemTypes/0/descriptions/0
Source references
4 source assertions{"name":"https://github.com/openedx/openedx-platform/commit/6fda1f120ff5a590d120ae1180185525f399c6d0","tags":["x_refsource_MISC"],"url":"https://github.com/openedx/openedx-platform/commit/6fda1f120ff5a590d120ae1180185525f399c6d0"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a56d6f6d6b4e0ea8b542cfdefb1449fe3b85210e5b72af6f1bed80385a0a8d9d · sha256:3bdadbcbf443196f… · /containers/cna/references/1
{"name":"https://github.com/openedx/openedx-platform/commit/70a56246dd9c9df57c596e64bdd8a11b1d9da054","tags":["x_refsource_MISC"],"url":"https://github.com/openedx/openedx-platform/commit/70a56246dd9c9df57c596e64bdd8a11b1d9da054"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a56d6f6d6b4e0ea8b542cfdefb1449fe3b85210e5b72af6f1bed80385a0a8d9d · sha256:3bdadbcbf443196f… · /containers/cna/references/2
{"name":"https://github.com/openedx/openedx-platform/security/advisories/GHSA-328g-7h4g-r2m9","tags":["x_refsource_CONFIRM"],"url":"https://github.com/openedx/openedx-platform/security/advisories/GHSA-328g-7h4g-r2m9"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a56d6f6d6b4e0ea8b542cfdefb1449fe3b85210e5b72af6f1bed80385a0a8d9d · sha256:3bdadbcbf443196f… · /containers/cna/references/0
{"tags":["exploit"],"url":"https://github.com/openedx/openedx-platform/security/advisories/GHSA-328g-7h4g-r2m9"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a56d6f6d6b4e0ea8b542cfdefb1449fe3b85210e5b72af6f1bed80385a0a8d9d · sha256:3bdadbcbf443196f… · /containers/adp/0/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.