Pending AI Enrichment

This vulnerability was recently detected via the live feed and has not yet been processed by Precogs AI's context enrichment engine. The data below represents raw telemetric data.

RAW NVD TELEMETRY

CVE-2026-53636

CVSS Base Score
4.7 MEDIUM
Primary Weakness
CWE-294
Published Date
Sep 2, 2026
Data Source
NVD API

Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 3a5ac85, a security vulnerability has been identified in the Open edX LMS platform's LTI (Learning Tools Interoperability) Provider implementation. The validate_timestamp_and_nonce function in lms/djangoapps/lti_provider/signature_validator.py does not validate OAuth nonces or timestamps, allowing an attacker who captures a valid LTI launch request to replay it an unlimited number of times without detection. This issue has been patched via commit 3a5ac85.

Related Vulnerabilitiesvia CWE-294

Is your system affected?

Precogs AI detects CVE-2026-53636 in compiled binaries, LLMs, and application layers — even without source code access.