Our colleague @mal had another look at OpenOLAT and found a nice RCE (CVE-2026-28228 and CVE-2026-28228). If you're interested, details can be found on our blog https://secfault-security.com/blog/openolat-ssti.html
Secfault Security - OpenOlat - RCE via Server-side Template Injection (SSTI) and OIDC Auth Bypass