PatchSiren cyber security CVE debrief
CVE-2026-97646 ningzichun CVE debrief
A weakness was identified in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. This affects an unknown function of the file admin/fun/getStudent.php. The manipulation of the argument sid causes authorization bypass. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
- Vendor
- ningzichun
- Product
- student-management-system
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-25
- Original CVE updated
- 2026-09-25
- Advisory published
- 2026-09-25
- Advisory updated
- 2026-09-25
Who should care
Defenders responsible for student-management-system deployments, especially those with publicly accessible admin interfaces, should assess exposure and potential exploitation risks.
Why it matters
CVE-2026-97646 is a medium-severity vulnerability in ningzichun student-management-system that allows for authorization bypass. Defenders should prioritize verifying exposure, assessing exploitation risks, and implementing compensating controls due to the publicly available exploit and lack of vendor response.
- Defenders must verify exposure of student-management-system deployments to potential authorization bypass attacks
- Publicly available exploit information increases the risk of attacks
- Lack of vendor response and patches requires defenders to implement compensating controls
Technical summary
The vulnerability affects an unknown function of the file admin/fun/getStudent.php in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. The manipulation of the argument sid causes authorization bypass, allowing for remote attacks. The exploit has been made publicly available. Defenders should prioritize verifying exposure of student-management-system deployments, especially those with publicly accessible admin interfaces, and assess the feasibility of exploitation given the available exploit information. The project was informed of the problem early through an issue report but has not responded yet.
Defensive priority
Defenders should prioritize verifying exposure of student-management-system deployments, especially those with publicly accessible admin interfaces, and assess the feasibility of exploitation given the available exploit information.
Recommended defensive actions
- Verify exposure of student-management-system deployments, especially those with publicly accessible admin interfaces
- Assess the feasibility of exploitation given the available exploit information
- Monitor for potential attacks using the publicly available exploit
- Implement compensating controls for exposed systems while remediation is scheduled and verified
- Review relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its description, CVSS score, and affected versions. However, the vendor has not responded to the issue report, and there is no information on official patches or mitigations.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-97646 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-97646
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-97646 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-97646
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/ningzichun/student-management-system/
-
Source reference
Unverified legacy reference
URL: https://github.com/ningzichun/student-management-system/issues/9
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/cve/CVE-2026-97646
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/910054
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/409748
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/409748/cti
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.