{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3asoarkeystudentmanagement/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:soarkey:studentmanagement:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-90787"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["StudentManagement (up to e08f7f1d5015af407aa4cca0ada3dea189b4937e)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","privilege-escalation"],"_cs_type":"advisory","_cs_vendors":["Soarkey"],"content_html":"\u003cp\u003eA security vulnerability (CVE-2026-90787) exists in the Soarkey StudentManagement application, specifically within the Registration Workflow component. The issue resides in the 'RegisterServlet.doPost' function located in 'code/WebContent/register.html'. The application fails to adequately validate the 'level' argument provided during the registration process. This flaw allows a remote, unauthenticated attacker to inject or manipulate the account privilege level, potentially granting unauthorized elevated access.\u003c/p\u003e\n\u003cp\u003eThe project uses commit hashes rather than formal versioning, and the vulnerability affects versions up to 'e08f7f1d5015af407aa4cca0ada3dea189b4937e'. As of the report date, the vendor has been notified but has not provided a patch or formal response. Given that exploit code is publicly available, organizations running this software are at risk of account takeover and unauthorized administrative access.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows remote attackers to register accounts with arbitrary privilege levels. This could result in complete system compromise if the attacker elevates their account to administrative status, leading to unauthorized access to student records, modification of data, or further exploitation of the underlying system infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eReview web server access logs for anomalous HTTP POST requests to 'register.html' or associated servlet endpoints containing an unexpected 'level' parameter.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation or temporary WAF rules to sanitize and restrict the 'level' parameter to expected integer ranges or predefined roles.\u003c/li\u003e\n\u003cli\u003eIf immediate patching is not possible, disable the self-registration functionality until the vendor provides an official update.\u003c/li\u003e\n\u003cli\u003eAudit existing user account levels for suspicious privilege assignments that do not align with expected user roles.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-14T15:33:40Z","date_published":"2026-09-14T15:33:40Z","id":"https://feed.craftedsignal.io/briefs/2026-09-soarkey-privilege-escalation/","summary":"The RegisterServlet component in Soarkey StudentManagement is vulnerable to improper privilege management, allowing remote attackers to manipulate user account levels during registration via the 'level' argument.","title":"Improper Privilege Management in Soarkey StudentManagement","url":"https://feed.craftedsignal.io/briefs/2026-09-soarkey-privilege-escalation/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:soarkey:studentmanagement:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}