PatchSiren

Portabilis CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW Portabilis CVE published 2026-02-06

CVE-2026-2015

A weakness in Portabilis i-Educar up to 2.10 allows for improper authorization due to a manipulation of the school_id argument in the FinalStatusImportService.php file. The attack can be executed remotely and a public exploit is available. Upgrading to version 2.11.0 addresses this issue. Defenders should verify exposure, prioritize upgrading to version 2.11.0, and monitor for exploitation attempts. Vulne [truncated]