Improper Privilege Management in Soarkey StudentManagement Registration Workflow
CVE-2026-90787
Key Information:
- Vendor
Soarkey
- Status
- Vendor
- CVE Published:
- 14 September 2026
Badges
What is CVE-2026-90787?
A flaw was discovered in the Soarkey StudentManagement application, specifically in the RegisterServlet.doPost function of the registration workflow component. This vulnerability allows attackers to manipulate user privilege levels, leading to unauthorized actions. The exploit can be executed remotely and existing defenses against such manipulations may not suffice. The project maintainers have been made aware of the issue through a reported concern, but no remediation has been issued as of yet. Publicly available exploits may pose a risk to users of the affected product.
Affected Version(s)
StudentManagement e08f7f1d5015af407aa4cca0ada3dea189b4937e
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
