Description
A vulnerability was identified in Soarkey StudentManagement up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. Affected is the function RegisterServlet.doPost of the file code/WebContent/register.html of the component Registration Workflow. Such manipulation of the argument level leads to improper privilege management. The attack can be launched remotely. The exploit is publicly available and might be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-14
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Assess Impact
AI Analysis

Impact

A flaw in the registration workflow allows an attacker to manipulate the level argument when registering a user. By modifying this argument the attacker can assign themselves or others higher privileges than intended. The vulnerability is a form of improper privilege escalation, which is reflected by the listed weaknesses CWE-266 and CWE-269. This can lead to accessing or modifying sensitive student data, changing grades, or performing administrative tasks.

Affected Systems

The affected product is Soarkey StudentManagement, a web‑based student management system. The specific function impacted is RegisterServlet.doPost in the register.html component. No versioning information is present, so all releases are potentially affected so system an update is released.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity, and the exploit is publicly available and can be launched remotely, though the EPSS score is unknown. The vulnerability is not listed in CISA’s KEV catalog. The exploit path involves remotely submitting a crafted registration request that includes a manipulated level value, suggesting that basic network exposure is sufficient to launch the attack. Given the lack of formal patch and public availability of the exploit, administrators should treat this as a tangible risk and attempt to mitigate it promptly.

Generated by OpenCVE AI on September 15, 2026 at 13:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Revoke the ability to set privilege levels via untrusted user input by hard‑coding the role assignment logic, ensuring that registration always assigns a default, non‑privileged role.
  • Validate the level parameter against an explicit whitelist of allowed values and reject any request that contains a value outside that set. Reject the request with a clear error message rather than silently granting higher privileges.
  • Implement additional controls such as role‑based access checks in all privileged actions, ensuring that even if execute administrative functions.

Generated by OpenCVE AI on September 15, 2026 at 13:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in Soarkey StudentManagement up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. Affected is the function RegisterServlet.doPost of the file code/WebContent/register.html of the component Registration Workflow. Such manipulation of the argument level leads to improper privilege management. The attack can be launched remotely. The exploit is publicly available and might be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.
Title Soarkey StudentManagement Registration Workflow register.html RegisterServlet.doPost privileges management
First Time appeared Soarkey
Soarkey studentmanagement
Weaknesses CWE-266
CWE-269
CPEs cpe:2.3:a:soarkey:studentmanagement:*:*:*:*:*:*:*:*
Vendors & Products Soarkey
Soarkey studentmanagement
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Soarkey Studentmanagement
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T15:37:50.837Z

Reserved: 2026-09-13T13:03:28.468Z

Link: CVE-2026-90787

cve-icon Vulnrichment

Updated: 2026-09-14T15:37:46.327Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T14:17:19.530

Modified: 2026-09-14T20:56:48.220

Link: CVE-2026-90787

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T14:00:11Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-269

    Improper Privilege Management