An authentication bypass issue in the LTI Provider allowed suspended users to authenticate. The flaw stemmed from missing enforcement of suspension state in LTI authentication handlers, permitting access that should have been blocked.