Improper Authentication in OUSL-GROUP BrinaryBrains School Student Management System
CVE-2026-10167

6.9MEDIUM

Key Information:

Vendor
CVE Published:
31 May 2026

Badges

👾 Exploit Exists🟡 Public PoC

What is CVE-2026-10167?

A vulnerability has been detected in the OUSL-GROUP BrinaryBrains School Student Management System, affecting the sign_auth_cookie function within the Login.php file of the MY_Controller component. By manipulating the role argument, an attacker can gain unauthorized access, compromising the system’s authentication process. This issue allows for remote exploitation and has been publicly disclosed, posing significant risks to user data and system integrity. The developers have been notified but have yet to address the concern.

Affected Version(s)

School Student Management System 1e70e5ad1125b86dca4ee086eb6bb121f17708b6

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Akirazz (VulDB User)
VulDB CNA Team
.