
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-26717 is a timing side-channel vulnerability in OpenFUN Richie (LMS) that allows remote attackers to forge valid HMAC signatures and bypass authentication. The flaw exists in src/richie/apps/courses/api.py within the sync_course_run_from_request function, which uses Python's non-constant-time == operator for HMAC signature comparison. It was published on February 25, 2026, and has a CVSS v3.1 base score of 4.8 (Medium) (Red Hat Advisory, Feedly).
The root cause is classified as CWE-208 (Observable Timing Discrepancy). The sync_course_runs_from_request function in api.py compared the incoming Authorization header against a computed HMAC signature using Python's standard == operator, which short-circuits on the first mismatched byte and leaks timing information. An unauthenticated remote attacker can exploit this by sending many crafted requests and measuring response time differences to iteratively determine valid HMAC signatures — a classic timing oracle attack (CAPEC-462: Cross-Domain Search Timing). No special privileges or user interaction are required, though the attack complexity is rated High due to the precision required for timing measurements. The fix replaces == with hmac.compare_digest(), which performs constant-time comparison (GitHub Commit, Red Hat Advisory).
Successful exploitation allows an unauthenticated remote attacker to forge valid HMAC signatures and bypass authentication on the sync_course_run_from_request API endpoint. This enables adversaries to impersonate legitimate systems and submit unauthorized course run synchronization requests, potentially leading to unauthorized access to course run data and integrity compromise of LMS content. Confidentiality and integrity impacts are both rated Low, with no availability impact (Red Hat Advisory, Feedly).
A proof-of-concept exploit is publicly available on GitHub (PoC), added on March 2, 2026. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score is approximately 0.077%, reflecting low but non-zero exploitation probability. The High attack complexity rating (requiring precise timing measurements) limits opportunistic exploitation (Feedly).
/api/v1.0/course-runs/ or equivalent sync endpoint that uses HMAC-based authentication.== comparison.sync_course_run_from_request endpoint, successfully bypassing authentication and injecting malicious course run data (GitHub Commit, PoC)./api/v1.0/course-runs/) from a single IP or small IP range with slightly varying Authorization header values; requests with statistically similar but incrementally differing HMAC signatures.sync_course_run_from_request outside of normal LMS integration schedules.The OpenFUN Richie project has issued a fix in commit a1b5bbda3403d7debb466c303a32852925fcba5f, which replaces the non-constant-time == operator with hmac.compare_digest() in the sync_course_runs_from_request function. Administrators should update to a version of Richie that includes this commit as soon as possible. As an interim workaround, restrict network-level access to the course run sync API endpoint to trusted IP addresses only, and monitor for anomalous timing-based request patterns targeting the endpoint (GitHub Commit, Feedly).
A technical write-up on the vulnerability was published on Medium, detailing the HMAC timing attack mechanics in OpenFUN Richie LMS (Medium Write-up). A security blog post was also published at infinitsec.net covering the timing attack vulnerability (Infinitsec Blog). Community reaction has been limited given the moderate severity and niche affected product.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."