CVE-2026-3111Disclosure

LOWCVSS 6.9 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Insecure Direct Object Reference (IDOR) vulnerability in Campus Educativa specifically at the endpoint '/archivos/usuarios/[ID]/[username]/thumb_AAxAA.jpg' (translated as 80x90 and 40x45). Successful exploitation of this vulnerability could allow an unauthenticated attacker to access the profile photos of all users via a manipulated URL, enabling them to collect user photos en masse. This could lead to these photos being used maliciously to impersonate identities, perform social engineering, link identities across platforms using facial recognition, or even carry out doxxing.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-16: 2Technical Details · 2026-03-16: 103-16
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • INCIBE-CERT@incibe_cert
    Disclosure

    ⚠️#INCIBEaviso | Múltiples vulnerabilidades en el Campus de Educativa #CVE CVE-2026-3110 y CVE-2026-3111 https://www.incibe.es/incibe-cert/alerta-temprana/avisos/multiples-vulnerabilidades-en-el-campus-de-educativa #AvisosDeSeguridad #TI #CNA

    Post summary

    The post announces the existence of CVE‑2026‑3110 and CVE‑2026‑3111 affecting an educational campus, but provides no further technical details or operational context.

    01000420
    42.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3111 Insecure Direct Object Reference (IDOR) vulnerability in Campus Educativa specifically at the endpoint '/archivos/usuarios/[ID]/[username]/thumb_AAxAA.jpg' (translated … https://www.cve.org/CVERecord?id=CVE-2026-3111

    Post summary

    A new IDOR vulnerability (CVE-2026-3111) has been disclosed for Campus Educativa, affecting a specific thumbnail endpoint that allows direct access to user files.

    00000140
    56.7K followersView on X

Explore more