PatchSiren cyber security CVE debrief
CVE-2026-3110 Educativa CVE debrief
An Insecure Direct Object Reference (IDOR) vulnerability in Campus Educativa allows unauthenticated attackers to export user enrollment data via a manipulated URL parameter. The vulnerable endpoint accepts a course ID parameter (`wid_cursoActual`) without proper authorization checks, enabling brute-force enumeration of course IDs to harvest usernames, names, email addresses, and phone numbers of all enrolled users. The vulnerability was disclosed by INCIBE-CERT and carries a HIGH severity CVSS 4.0 score of 8.7. As of the CVE modification date (2026-05-19), the NVD entry remains in 'Deferred' status, indicating pending analysis. No known exploitation in ransomware campaigns has been documented.
- Vendor
- Educativa
- Product
- Campus
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-16
- Original CVE updated
- 2026-05-19
- Advisory published
- 2026-03-16
- Advisory updated
- 2026-05-19
Who should care
Educational institutions deploying Campus Educativa software; security teams responsible for student information systems; privacy officers managing GDPR or FERPA compliance for educational records; incident response teams monitoring for bulk PII exfiltration patterns.
Technical summary
The vulnerability exists in the `/administracion/admin_usuarios.cgi` endpoint where the `wid_cursoActual` parameter accepts arbitrary course identifiers without session-based authorization validation. The endpoint exports XLSX files containing PII of enrolled users. An attacker can iterate through sequential or predictable course ID values to harvest data across the entire user base. The CVSS 4.0 vector (AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N) reflects network accessibility, low attack complexity, no required privileges, and high confidentiality impact with no integrity or availability impact.
Defensive priority
HIGH
Recommended defensive actions
- Implement strict authorization checks on the /administracion/admin_usuarios.cgi endpoint to verify the requesting user has legitimate access to the specified course ID
- Replace predictable sequential course IDs with non-enumerable identifiers (UUIDs) to prevent brute-force attacks
- Add rate limiting and anomaly detection for repeated requests to the export endpoint with varying ID parameters
- Review and audit all similar export endpoints in the application for equivalent IDOR vulnerabilities
- Ensure access logs capture client IP, user session, and requested course ID for forensic analysis
Evidence notes
Vulnerability description sourced from NVD record with INCIBE-CERT advisory as primary reference. CVSS 4.0 vector confirms network attack vector with no privileges required. Vendor identification marked as low confidence due to 'Unknown Vendor' classification in source data; 'Campus Educativa' appears to be the product name with INCIBE as the coordinating authority.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-3110 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-3110
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-3110 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-3110
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-educativa-campus
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.