CVE-2026-64963
Received Received - Intake

Path Traversal in ATutor LMS

Vulnerability report for CVE-2026-64963, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-20

Last updated on: 2026-08-20

Assigner: CERT.PL

Description

A path traversal vulnerability in ATutor allows an authenticated user to access files from other course directories when the AT_FORCE_GET_FILE configuration option is enabled. This can lead to unauthorized access to files and disclosure of information about the filesystem structure. Product is no longer actively supported and the vulnerabilities have not been fixed. Only version 2.2.4 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-20
Last Modified
2026-08-20
Generated
2026-08-20
AI Q&A
2026-08-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
atutor atutor to 2.2.4 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a path traversal vulnerability in ATutor where an authenticated user can access files from other course directories if the AT_FORCE_GET_FILE option is enabled. This allows unauthorized access to files and exposes filesystem structure details.

Detection Guidance

Since ATutor is no longer supported and the vulnerability is confirmed in version 2.2.4, detection may involve checking for the AT_FORCE_GET_FILE configuration option in ATutor installations. No specific commands are provided in the context.

Impact Analysis

An attacker could read sensitive files outside their intended course directory, potentially exposing confidential data like user information or system files. Since ATutor is no longer supported, patches are unavailable.

Compliance Impact

This vulnerability could lead to unauthorized data access, violating GDPR (data protection) and HIPAA (health data privacy) by exposing sensitive user information. Non-compliance risks fines and legal consequences.

Mitigation Strategies

Immediate mitigation steps include disabling the AT_FORCE_GET_FILE configuration option if enabled, upgrading to a supported version if available, or migrating to an alternative platform. Since no patches exist, consider discontinuing use of ATutor 2.2.4.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-64963. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart