Improper Authentication in OUSL-GROUP BrinaryBrains School Student Management System
CVE-2026-10167
Key Information:
- Vendor
Ousl-group-brinarybrains
- Vendor
- CVE Published:
- 31 May 2026
Badges
What is CVE-2026-10167?
A vulnerability has been detected in the OUSL-GROUP BrinaryBrains School Student Management System, affecting the sign_auth_cookie function within the Login.php file of the MY_Controller component. By manipulating the role argument, an attacker can gain unauthorized access, compromising the system’s authentication process. This issue allows for remote exploitation and has been publicly disclosed, posing significant risks to user data and system integrity. The developers have been notified but have yet to address the concern.
Affected Version(s)
School Student Management System 1e70e5ad1125b86dca4ee086eb6bb121f17708b6
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
