PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-97646 ningzichun CVE debrief

A weakness was identified in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. This affects an unknown function of the file admin/fun/getStudent.php. The manipulation of the argument sid causes authorization bypass. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

Vendor
ningzichun
Product
student-management-system
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-25
Original CVE updated
2026-09-25
Advisory published
2026-09-25
Advisory updated
2026-09-25

Who should care

Defenders responsible for student-management-system deployments, especially those with publicly accessible admin interfaces, should assess exposure and potential exploitation risks.

Why it matters

CVE-2026-97646 is a medium-severity vulnerability in ningzichun student-management-system that allows for authorization bypass. Defenders should prioritize verifying exposure, assessing exploitation risks, and implementing compensating controls due to the publicly available exploit and lack of vendor response.

  • Defenders must verify exposure of student-management-system deployments to potential authorization bypass attacks
  • Publicly available exploit information increases the risk of attacks
  • Lack of vendor response and patches requires defenders to implement compensating controls

Technical summary

The vulnerability affects an unknown function of the file admin/fun/getStudent.php in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. The manipulation of the argument sid causes authorization bypass, allowing for remote attacks. The exploit has been made publicly available. Defenders should prioritize verifying exposure of student-management-system deployments, especially those with publicly accessible admin interfaces, and assess the feasibility of exploitation given the available exploit information. The project was informed of the problem early through an issue report but has not responded yet.

Defensive priority

Defenders should prioritize verifying exposure of student-management-system deployments, especially those with publicly accessible admin interfaces, and assess the feasibility of exploitation given the available exploit information.

Recommended defensive actions

  • Verify exposure of student-management-system deployments, especially those with publicly accessible admin interfaces
  • Assess the feasibility of exploitation given the available exploit information
  • Monitor for potential attacks using the publicly available exploit
  • Implement compensating controls for exposed systems while remediation is scheduled and verified
  • Review relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its description, CVSS score, and affected versions. However, the vendor has not responded to the issue report, and there is no information on official patches or mitigations.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-97646 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-97646

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-97646 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-97646

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.