LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-7491 - Vulnerability Analysis

HighCVSS: 8.1

Last Updated: May 2, 2026

Zyosoft School App - Broken Access Control

Published: May 2, 2026Updated: May 2, 2026Remote Exploitable

Overview

Zyosoft School App contains a broken access control caused by insecure direct object reference, letting authenticated remote attackers read and modify other users' data, exploit requires authentication.

Severity & Score

Severity: High
CVSS Score: 8.1

Impact

Authenticated attackers can read and modify other users' data, leading to data tampering and information disclosure.

Mitigation

Update to the latest version with access control fixes.

Details

CVE ID
CVE-2026-7491
Severity
High
CVSS Score
8.1
Type
broken_access_control
Status
new

CWE

  • CWE-639

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N