Missing Authentication Vulnerability in GibbonEdu Gibbon Unit Planner
CVE-2026-97864

6.9MEDIUM

Key Information:

Vendor

Gibbonedu

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-97864?

A notorious missing authentication vulnerability has been detected in the GibbonEdu Gibbon application, specifically in the Unit Planner component's makeBlock function. This issue arises from improper handling of the gibbonUnitBlockID/mode argument, allowing unauthorized users to execute actions remotely without authentication. Publicly disclosed exploits may pose a significant risk to systems running affected versions, emphasizing the importance of upgrading to version 31.0.00 to mitigate such threats effectively. To resolve this critical flaw, users are strongly advised to update their installations as soon as possible.

Affected Version(s)

Gibbon 30.0.01

Gibbon 31.0.00

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

f_asadbek1 (VulDB User)
.