{"id":"CVE-2026-89176","title":"WeenyGenius, a computer lab management system developed by Howyar Technologies, has a Missing Authentication vulnerability","summary":"WeenyGenius, a computer lab management system developed by Howyar Technologies, has a Missing Authentication vulnerability. Unauthenticated attackers on the same network can easily spoof student or teacher endpoints. Impersonating a stud…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-306"],"vendor":"Howyar","product":"WeenyGenius","affected":["WeenyGenius <= 12.2.031"],"published":"2026-09-11","updated":"2026-09-11","sourceUpdated":"2026-09-11T16:17:50.073","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-89176","references":[{"url":"https://www.twcert.org.tw/en/cp-139-11200-ffc3c-2.html","label":"twcert@cert.org.tw"},{"url":"https://www.twcert.org.tw/tw/cp-132-11201-658c0-1.html","label":"twcert@cert.org.tw"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-11T15:40:19.283969Z"},"epss":0.00249,"epssPercentile":0.16587,"ingestedAt":"2026-09-11T16:45:47.860Z","slug":"CVE-2026-89176","body":"## Overview\n\nWeenyGenius, a computer lab management system developed by Howyar Technologies, has a Missing Authentication vulnerability. Unauthenticated attackers on the same network can easily spoof student or teacher endpoints. Impersonating a student can disrupt normal classroom operations, whereas impersonating a teacher can induce student computers to initiate connections, thereby gaining remote control over the student endpoints.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}