Description
`tts-be` is a backend for a timetable selector that aims to help students better choose their class schedules. Versions prior to 2.1.0 have a Broken Access Control vulnerability across several API endpoints (such as `/api/student/{id}/photo` and `/api/course_unit/{id}/exchange/metadata`). By chaining these unauthenticated endpoints, a remote attacker can use the backend as an open proxy to bypass authorization checks, allowing for the enumeration and extraction of sensitive Personally Identifiable Information (PII) from upstream university systems. The exposed data includes full names, student IDs, class schedules, and photos. This issue was fixed in version 2.1.0.
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access to Sensitive Data
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a broken access control flaw in the tts‑be backend, which permits unauthenticated requests to several API endpoints such as "/api/student/{id}/photo" and "/api/course_unit/{id}/exchange/metadata". By chaining these endpoints, a remote attacker can treat the service as an open proxy, circumventing the intended authorization checks and extracting personally identifiable information from upstream university systems, including full names, student IDs, class schedules, and photos. The flaw enables an attacker to read data that should be protected, leading to a confidentiality breach.

Affected Systems

The affected product is NIAEFEUP’s tts‑be timetable‑selection backend. Any deployment of tts‑be versions earlier than 2.1.0 is vulnerable. The issue has been remedied in version 2.1.0, which enforces proper access controls on all exposed APIs.

Risk and Exploitability

With a CVSS score of 7.5, the vulnerability presents a moderate‑to‑high severity risk. The EPSS score of less than 1% indicates a low probability of exploitation under current conditions, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, relying on an attacker sending HTTP requests to the exposed endpoints over the internet or an insecure internal network. If the service is publicly accessible, the impact could rapidly spread, as attackers can repeatedly enumerate user identities and associated data, exploiting the lack of authentication and authorization controls.

Generated by OpenCVE AI on September 18, 2026 at 14:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the tts‑be application to version 2.1.0 or later, which corrects the broken access control bug.
  • Configure the application to require authentication on all API endpoints and verify that proper role‑based access control is enforced for sensitive data operations.
  • Perform a thorough security review of all remaining endpoints to ensure they do not permit similar unauthenticated data access, and apply defensive coding practices to prevent broken access control in future releases.

Generated by OpenCVE AI on September 18, 2026 at 14:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Niaefeup
Niaefeup tts-be
Vendors & Products Niaefeup
Niaefeup tts-be

Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description `tts-be` is a backend for a timetable selector that aims to help students better choose their class schedules. Versions prior to 2.1.0 have a Broken Access Control vulnerability across several API endpoints (such as `/api/student/{id}/photo` and `/api/course_unit/{id}/exchange/metadata`). By chaining these unauthenticated endpoints, a remote attacker can use the backend as an open proxy to bypass authorization checks, allowing for the enumeration and extraction of sensitive Personally Identifiable Information (PII) from upstream university systems. The exposed data includes full names, student IDs, class schedules, and photos. This issue was fixed in version 2.1.0.
Title `tts-be` application has a Broken Access Control vulnerability
Weaknesses CWE-200
CWE-306
CWE-639
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T13:58:11.542Z

Reserved: 2026-09-09T21:22:45.435Z

Link: CVE-2026-88065

cve-icon Vulnrichment

Updated: 2026-09-16T13:58:07.195Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T21:16:43.367

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-88065

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T14:30:09Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-306

    Missing Authentication for Critical Function

  • CWE-639

    Authorization Bypass Through User-Controlled Key