{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/lab-management/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:howyar:weenygenius:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-89176"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WeenyGenius"],"_cs_severities":["high"],"_cs_tags":["vulnerability","authentication-bypass","lab-management"],"_cs_type":"advisory","_cs_vendors":["Howyar Technologies"],"content_html":"\u003cp\u003eHowyar Technologies WeenyGenius, a computer lab management system, is affected by a missing authentication vulnerability (CVE-2026-89176). This flaw allows an unauthenticated attacker present on the local network to spoof the identity of either a student or teacher endpoint. By successfully masquerading as a teacher node, an attacker can transmit unauthorized commands to student workstations. This capability enables the attacker to initiate connections from student machines, potentially leading to unauthorized remote control and the disruption of classroom activities. Because the application lacks sufficient authentication mechanisms, any attacker with network connectivity to the lab environment can interact with the management service and influence endpoint behavior without providing credentials.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to gain remote control over student workstations within a laboratory environment. This can lead to the total disruption of classroom operations, unauthorized access to student work, and potential further lateral movement within the network if student endpoints are leveraged as a beachhead.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eDefenders should prioritize the identification of WeenyGenius deployments within their network environment and ensure they are segmented from untrusted users. If patching is unavailable, implement network-level access control lists to restrict traffic to the management service to known authorized teacher workstations only.\u003c/p\u003e\n","date_modified":"2026-09-11T09:12:39Z","date_published":"2026-09-11T09:12:39Z","id":"https://feed.craftedsignal.io/briefs/2026-09-weenygenius-vuln/","summary":"WeenyGenius by Howyar Technologies contains a missing authentication vulnerability allowing unauthenticated network-adjacent attackers to spoof teacher or student roles and achieve remote control of student workstations.","title":"Unauthenticated Endpoint Spoofing in WeenyGenius","url":"https://feed.craftedsignal.io/briefs/2026-09-weenygenius-vuln/"}],"language":"en","title":"CraftedSignal Threat Feed - Lab-Management","version":"https://jsonfeed.org/version/1.1"}