CVE-2026-7491Disclosure

LOWCVSS 8.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

School App developed by Zyosoft has an Insecure Direct Object Reference vulnerability, allowing authenticated remote attackers to modify a specific parameter to read and modify other users' data.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-05-02); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-05-02: 3Mentions · 2026-05-14: 1Patch / Workaround · 2026-05-14: 1Technical Details · 2026-05-02: 3Technical Details · 2026-05-14: 105-0205-14
Signal classification1 categories
Disclosure
4100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-023
Disclosure3
2026-05-141
Disclosure1
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-7491 School App developed by Zyosoft has an Insecure Direct Object Reference vulnerability, allowing authenticated remote attackers to modify a specific parameter to read an… https://www.cve.org/CVERecord?id=CVE-2026-7491

    Post summary

    The statement announces CVE-2026-7491, an IDOR flaw in Zyosoft’s School App that allows authenticated remote users to alter a parameter to read sensitive data.

    00010258
    57.4K followersView on X
  • ADK Cyber@ADKCyber
    Disclosure

    A new CVE (CVE-2026-7491) exposes Zyosoft’s School App to data modification risks due to an Insecure Direct Object Reference vulnerability. If your organization uses this app, review access controls and patch promptly to protect sensitive data. #Cybersecurity

    Post summary

    A newly identified CVE-2026-7491 in Zyosoft’s School App exposes an insecure direct object reference that could allow data tampering, prompting users to review access controls and apply patches promptly.

    0000046
    80 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7491 Insecure Direct Object Reference in Zyosoft School App Allows Data Access Modification https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7491

    Post summary

    The text announces the discovery of an IDOR vulnerability (CVE-2026-7491) in Zyosoft School App, with no additional details on exploitation, patches, or PoCs.

    0000051
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-7491 School App developed by Zyosoft has an Insecure Direct Object Reference vulnerability, allowing authenticated remote attackers to modify a specific parameter to read an… https://www.cve.org/CVERecord?id=CVE-2026-7491 ----- Traducción: CVE-2026-7491 La … http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-7491, describing an IDOR flaw in Zyosoft’s School App that permits authenticated remote attackers to manipulate a parameter to read data, but it provides no PoC, exploit, or patch information.

    0000025
    75 followersView on X

Explore more