Skip to content
Threat Feed
high advisory

Unauthenticated Endpoint Spoofing in WeenyGenius

WeenyGenius by Howyar Technologies contains a missing authentication vulnerability allowing unauthenticated network-adjacent attackers to spoof teacher or student roles and achieve remote control of student workstations.

CVE search metadata

CVE search record: CVE-2026-89176. Severity: high. CVSS: 8.8. KEV: no. Product: WeenyGenius. Brief: Unauthenticated Endpoint Spoofing in WeenyGenius. Brief link: https://feed.craftedsignal.io/briefs/2026-09-weenygenius-vuln/

Howyar Technologies WeenyGenius, a computer lab management system, is affected by a missing authentication vulnerability (CVE-2026-89176). This flaw allows an unauthenticated attacker present on the local network to spoof the identity of either a student or teacher endpoint. By successfully masquerading as a teacher node, an attacker can transmit unauthorized commands to student workstations. This capability enables the attacker to initiate connections from student machines, potentially leading to unauthorized remote control and the disruption of classroom activities. Because the application lacks sufficient authentication mechanisms, any attacker with network connectivity to the lab environment can interact with the management service and influence endpoint behavior without providing credentials.

Impact

Successful exploitation allows unauthenticated attackers to gain remote control over student workstations within a laboratory environment. This can lead to the total disruption of classroom operations, unauthorized access to student work, and potential further lateral movement within the network if student endpoints are leveraged as a beachhead.

Recommendation

Defenders should prioritize the identification of WeenyGenius deployments within their network environment and ensure they are segmented from untrusted users. If patching is unavailable, implement network-level access control lists to restrict traffic to the management service to known authorized teacher workstations only.

Mitigations

Isolate WeenyGenius management traffic via network segmentation

immediate IT Operations

CVE-2026-89176