LOW
Portabilis
CVE published 2026-02-06
CVE-2026-2015
A weakness in Portabilis i-Educar up to 2.10 allows for improper authorization due to a manipulation of the school_id argument in the FinalStatusImportService.php file. The attack can be executed remotely and a public exploit is available. Upgrading to version 2.11.0 addresses this issue. Defenders should verify exposure, prioritize upgrading to version 2.11.0, and monitor for exploitation attempts. Vulne [truncated]