Reflected XSS flaws found in ATutor LMS
CERT Polska disclosed two reflected XSS vulnerabilities in unsupported ATutor e-learning software, allowing arbitrary JavaScript execution via crafted URLs.
CERT Polska coordinated disclosure of two reflected cross-site scripting vulnerabilities in ATutor, an open-source learning management system that is no longer actively maintained. CVE-2026-6909 affects the /install/upgrade.php endpoint, while CVE-2026-6956 affects /install/install.php. Both flaws allow an attacker to craft a malicious URL that, when opened by a victim, executes arbitrary JavaScript in the browser context.
Only version 2.2.4 was confirmed vulnerable during testing; other versions were not tested but could also be affected. The ATutor maintainers were notified early in the disclosure process but did not respond with technical details or a confirmed vulnerable version range, and since the product is no longer actively supported, no patch is expected. Organizations still running ATutor should consider migrating to a supported alternative, as these vulnerabilities are likely to remain unpatched.
The vulnerabilities were reported by researchers Michał Majchrowicz, Marcin Wyczechowski, and Pawel Zdunek of AFINE through CERT Polska's coordinated vulnerability disclosure process. There is no indication of active exploitation in the wild at this time.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-6909
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free