Description
A security flaw has been discovered in zhistaredu StarTraining up to 3.8.1. This affects the function checkRoleAllowed of the file SysRoleServiceImpl.java of the component dataScope Endpoint. The manipulation results in missing authorization. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-27
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Access Control Bypass
Action: Assess Impact
AI Analysis

Impact

A vulnerability was identified in the StarTraining platform that allows an attacker to bypass access controls by manipulating the checkRoleAllowed method in the SysRoleServiceImpl class of the dataScope endpoint. According to the description, the flaw results in missing authorization checks, enabling unauthorized users to access or modify data through this endpoint. The weakness corresponds to CWE‑862 and CWE‑863.

Affected Systems

The affected product is zhistaredu StarTraining, versions up to and including 3.8.1. No other versions or subcomponents are specified as affected. Users running these versions should consider this system vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate impact, and the EPSS score is not available. The vulnerability is not listed in CISA’s KEV catalog. Exploit code has been released publicly and can be triggered remotely. Given that the attack can be performed from outside the network, administrators should consider the risk moderate to high in environments where the dataScope endpoint is exposed. No official patch or workaround has been published by the vendor.

Generated by OpenCVE AI on September 27, 2026 at 22:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check whether a vendor patch or security update for the StarTraining 3.8.1 or later release is available, and apply it as soon as possible.
  • Inspect the implementation of checkRoleAllowed to confirm that every data scope operation requires an explicit authorization check; add missing pre‑authorization logic such as @PreAuthorize annotations.
  • Limit access to the dataScope endpoint by configuring role‑based access controls, enforcing authentication, and monitoring access logs for suspicious activity.

Generated by OpenCVE AI on September 27, 2026 at 22:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 27 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in zhistaredu StarTraining up to 3.8.1. This affects the function checkRoleAllowed of the file SysRoleServiceImpl.java of the component dataScope Endpoint. The manipulation results in missing authorization. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Title zhistaredu StarTraining dataScope Endpoint SysRoleServiceImpl.java checkRoleAllowed authorization
First Time appeared Zhistaredu
Zhistaredu startraining
Weaknesses CWE-862
CWE-863
CPEs cpe:2.3:a:zhistaredu:startraining:*:*:*:*:*:*:*:*
Vendors & Products Zhistaredu
Zhistaredu startraining
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Zhistaredu Startraining
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-27T20:45:08.786Z

Reserved: 2026-09-27T03:37:52.514Z

Link: CVE-2026-100879

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-27T21:17:01.283

Modified: 2026-09-27T21:17:01.283

Link: CVE-2026-100879

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T22:30:17Z

Weaknesses