In Totara LMS v19.1.5 and before, the forgot password API does not implement rate limiting for the target email address. which can be used for an Email Bombing attack.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://github.com/saykino/CVE-2026-31283 |
|
| https://totara.com/ |
|
History
Wed, 15 Apr 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Missing Rate Limiting on Totara LMS Forgot Password API Allows Email Bombing |
Tue, 14 Apr 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 14 Apr 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Missing Rate Limiting on Totara LMS Forgot Password API Allows Email Bombing | |
| Weaknesses | CWE-770 |
Tue, 14 Apr 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Totara
Totara lms |
|
| Vendors & Products |
Totara
Totara lms |
Mon, 13 Apr 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Totara LMS v19.1.5 and before, the forgot password API does not implement rate limiting for the target email address. which can be used for an Email Bombing attack. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-14T16:32:37.891Z
Reserved: 2026-03-09T00:00:00.000Z
Link: CVE-2026-31283
Updated: 2026-04-14T15:41:49.753Z
Status : Received
Published: 2026-04-13T15:17:33.220
Modified: 2026-04-14T17:16:50.190
Link: CVE-2026-31283
No data.
OpenCVE Enrichment
Updated: 2026-04-15T15:45:07Z