Missing Authentication Flaw in WeenyGenius by Howyar Technologies
CVE-2026-89176

8.7HIGH

Key Information:

Vendor

Howyar

Vendor
CVE Published:
11 September 2026

What is CVE-2026-89176?

The WeenyGenius system by Howyar Technologies exhibits a significant Missing Authentication vulnerability. This flaw allows unauthenticated attackers on the same network to impersonate either students or teachers. Such impersonation can lead to severe disruptions in classroom activities. Attackers masquerading as students may interrupt normal operations, while those impersonating teachers could potentially gain unauthorized remote access to student endpoints, allowing for control over their computers. This vulnerability raises critical concerns regarding network security and the integrity of the classroom environment.

Affected Version(s)

WeenyGenius 0 <= 12.2.031

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.