CVE-2026-5642Disclosure

LOWCVSS 5.5 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was determined in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This affects an unknown function of the file /viva/update.php of the component HTTP POST Request Handler. This manipulation of the argument Name causes improper authorization. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-266CWE-285

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-06: 3Technical Details · 2026-04-06: 204-06
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5642 Improper Authorization in Cyber-III Student-Management-System HTTP POST Request Handler https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5642

    Post summary

    A concise CVE disclosure identifies an improper authorization flaw in the Cyber-III Student-Management-System HTTP POST handler, with no additional details on PoC, exploitation, or patches.

    0000055
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-5642 A vulnerability was determined in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This affects an unknown function of the file /viva… https://www.cve.org/CVERecord?id=CVE-2026-5642 ----- Traducción: CVE-2026-5642 Se … http://infoflow.cloud`

    Post summary

    The tweet merely announces the identification of CVE‑2026‑5642 in Cyber‑III Student‑Management‑System and links to its CVE record, with no additional technical or exploit information.

    0000033
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5642 A vulnerability was determined in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This affects an unknown function of the file /viva… https://www.cve.org/CVERecord?id=CVE-2026-5642

    Post summary

    The post announces CVE‑2026‑5642 as a weakness in the Cyber‑III student‑management system, noting the relevant commit hash and file path but providing no exploitation proof, patches, or claims of active attacks.

    00000285
    57.0K followersView on X

Explore more