CVE-2026-7491 - Vulnerability Analysis
HighCVSS: 8.1Last Updated: May 2, 2026
Zyosoft School App - Broken Access Control
Published: May 2, 2026Updated: May 2, 2026Remote Exploitable
Overview
Zyosoft School App contains a broken access control caused by insecure direct object reference, letting authenticated remote attackers read and modify other users' data, exploit requires authentication.
Severity & Score
Severity: High
CVSS Score: 8.1
Impact
Authenticated attackers can read and modify other users' data, leading to data tampering and information disclosure.
Mitigation
Update to the latest version with access control fixes.
References
Related Resources
Details
- CVE ID
- CVE-2026-7491
- Severity
- High
- CVSS Score
- 8.1
- Type
- broken_access_control
- Status
- new
CWE
- CWE-639
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N