CVE-2026-10619
7.3 HIGHA vulnerability was detected in sayan365 student-management-system up to 7f3c9ce7d410332335c2affac93a385485051800
Published: 2026-06-02 · Last updated: 2026-06-04
Severity and scoring
- CVSS
- 7.3 HIGH
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- CWE
- CWE-287
Description
A vulnerability was detected in sayan365 student-management-system up to 7f3c9ce7d410332335c2affac93a385485051800. This impacts an unknown function. The manipulation results in improper authentication. The attack can be executed remotely. The exploit is now public and may be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. Multiple endpoints are affected. The project was informed of the problem early through an issue report but has not responded yet.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2026-10619
- [Other]https://github.com/sayan365/student-management-system/
- [Other]https://github.com/sayan365/student-management-system/issues/3
- [Other]https://github.com/sayan365/student-management-system/issues/4
- [Other]https://vuldb.com/cve/CVE-2026-10619
- [Other]https://vuldb.com/submit/829545
- [Other]https://vuldb.com/submit/829562
- [Other]https://vuldb.com/submit/829566
- [Other]https://vuldb.com/submit/829567
- [Other]https://vuldb.com/submit/829568
- [Other]https://vuldb.com/submit/829569
- [Other]https://vuldb.com/vuln/367927
- [Other]https://vuldb.com/vuln/367927/cti
Related CVEs
Same CWE
- CVE-2026-12183 — Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux contains an Improper Authentication vulnerabili... (9.8 CRITICAL)
- CVE-2026-50623 — An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF (6.5 MEDIUM)
- CVE-2026-48611 — Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading t... (9.8 CRITICAL)
- CVE-2026-40995 — X509AuthenticationProvider could issue a fully authenticated X509AuthenticationToken when a presented certificate mapped to UserDetails, ... (5.4 MEDIUM)
- CVE-2026-47166 — ImageMagick is free and open-source software used for editing and manipulating digital images (5.7 MEDIUM)