CVE-2026-25753Disclosure(prasklatechnology / placipy)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application uses a hard-coded, static default password for all newly created student accounts. This results in mass account takeover, allowing any attacker to log in as any student once the password is known.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-259

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • placipy

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-02-06); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Products
placipy

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-06: 2Mentions · 2026-02-15: 1PoC Mentioned / Linked · 2026-02-15: 1Technical Details · 2026-02-06: 202-0602-15
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-062
Disclosure2
2026-02-151
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-25753 PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application uses a hard-coded, static default password for all n… https://www.cve.org/CVERecord?id=CVE-2026-25753

    Post summary

    CVE-2026-25753 discloses a hard‑coded default password in PlaciPy, presenting a credential compromise risk, but no PoC, patch, or active exploitation is reported.

    00010169
    56.5K followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    Disclosure

    🚨 #CVE-2026-25753 Exposed: How a Simple Credential Flaw Can Lead to Mass #Account Takeover + Video https://undercodetesting.com/cve-2026-25753-exposed-how-a-simple-credential-flaw-can-lead-to-mass-account-takeover-video/ Educational Purposes!

    Post summary

    The tweet announces CVE-2026-25753, a credential flaw that can lead to mass account takeover, and links to a video demonstration for educational purposes.

    0000037
    387 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-25753: PlaciPy has a Hard-Coded Default... Hard-coded student password in PlaciPy 1.0.0 enables trivial mass account takeover - zero auth complexity with full stu... https://zerodaysignal.com/vulnerability/CVE-2026-25753 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE‑2026‑25753, highlighting a hard‑coded password in PlaciPy 1.0.0 that permits mass account takeover, but it does not provide a PoC, exploit code, or patch information.

    0000058
    132 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appprasklatechnologyplacipy1.0.0--

Explore more