CVE-2026-30707Disclosure

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An issue was discovered in SpeedExam Online Examination System (SaaS) after v.FEV2026. It allows Broken Access Control via the ReviewAnswerDetails ASP.NET PageMethod. Authenticated attackers can bypass client-side restrictions and invoke this method directly to retrieve the full answer key. The provider states that this issue is "Fixed in [02/2026] backend service update."

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-17); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-17: 2Mentions · 2026-03-18: 1Technical Details · 2026-03-17: 2Technical Details · 2026-03-18: 103-1703-18
Signal classification1 categories
Disclosure
3100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-172
Disclosure2
2026-03-181
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-30707 An issue was discovered in SpeedExam Online Examination System (SaaS) after v.FEV2026. It allows Broken Access Control via the ReviewAnswerDetails http://ASP.NET PageMethod.… https://www.cve.org/CVERecord?id=CVE-2026-30707

    Post summary

    The text announces CVE-2026-30707 as a broken access control issue in SpeedExam Online Examination System, providing a link to its CVE record but no further details.

    00010158
    56.7K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-30707 - High An issue was discovered in SpeedExam Online Examination System (SaaS) after v.FEV2026. It allows Broken Access Control via the ReviewAnswerDetails http://ASP.NET PageMethod. Authenticated attackers ... https://www.thehackerwire.com/vulnerability/CVE-2026-30707/ https://t.co/odGMMvr7Im

    Post summary

    High‑severity broken access control vulnerability in SpeedExam Online Examination System, enabling authenticated attackers to invoke a PageMethod; no PoC, exploit code, or active exploitation noted.

    0000040
    138 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-30707 Broken Access Control in SpeedExam Online Examination System via ReviewAnswerDetails PageMethod https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-30707

    Post summary

    This text announces a broken access control vulnerability (CVE‑2026‑30707) in SpeedExam's ReviewAnswerDetails page method, but does not provide any evidence of exploitation, PoC, or remedial action.

    0000046
    4.0K followersView on X

Explore more