PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-100878 zhistaredu CVE debrief

A vulnerability was identified in zhistaredu StarTraining up to 3.8.1. Affected by this issue is the function SysUser.isAdmin of the file edu-common/src/main/java/com/edu/common/core/domain/entity/SysUser.java of the component authRole Endpoint. The manipulation of the argument userId/roleIds leads to authorization bypass. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.

Vendor
zhistaredu
Product
StarTraining
CVSS
LOW 2.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-27
Original CVE updated
2026-09-27
Advisory published
2026-09-27
Advisory updated
2026-09-27

Who should care

Defenders responsible for zhistaredu StarTraining deployments up to 3.8.1 should assess exposure and prioritize verification of the authRole Endpoint. This includes reviewing system configurations, user roles, and access controls to mitigate potential risks. Additionally, defenders should focus on verifying affected systems, implementing compensating controls, and monitoring for potential exploitation attempts.

Why it matters

CVE-2026-100878 is a low-severity vulnerability in zhistaredu StarTraining up to 3.8.1 that allows authorization bypass in the authRole Endpoint. Defenders should prioritize verifying affected versions, assessing exposure, and implementing compensating controls to prevent unauthorized access.

  • Potential unauthorized access to sensitive data or functionality
  • Possible lateral movement within the network
  • Need for verification of affected versions and exposure
  • Priority for implementing compensating controls

Technical summary

The vulnerability is located in the SysUser.isAdmin function of the edu-common/src/main/java/com/edu/common/core/domain/entity/SysUser.java file in the authRole Endpoint component of zhistaredu StarTraining up to 3.8.1. The manipulation of the userId/roleIds argument leads to authorization bypass, allowing remote attacks. Defenders should prioritize verifying the affected versions and assessing exposure of the authRole Endpoint in zhistaredu StarTraining up to 3.8.1. This involves reviewing system configurations, user roles, and access controls to mitigate potential risks.

Defensive priority

Defenders should prioritize verifying the affected versions and assessing exposure of the authRole Endpoint in zhistaredu StarTraining up to 3.8.1.

Recommended defensive actions

  • Verify the affected versions of zhistaredu StarTraining and assess exposure of the authRole Endpoint
  • Implement compensating controls to prevent unauthorized access to the authRole Endpoint
  • Monitor for potential exploitation attempts
  • Review relevant logs for exposed assets that need extra review
  • Track exceptions and retest remediated assets
  • whoShouldCare
  • technicalSummary

Evidence notes

The CVE record and NVD entry provide limited information about the vulnerability. The exploit is publicly available, but there is no information on actual exploitation or impact. Defenders should verify the affected versions of zhistaredu StarTraining and assess exposure of the authRole Endpoint. The lack of detailed information necessitates a cautious approach, focusing on verifying affected systems and implementing compensating controls.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-100878 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-100878

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-100878 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-100878

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.