---
id: CVE-2026-2015
title: A weakness has been identified in Portabilis i-Educar up to 2.10
summary: >-
  A weakness has been identified in Portabilis i-Educar up to 2.10. Affected is
  an unknown function of the file FinalStatusImportService.php of the component
  Final Status Import. Executing a manipulation of the argument school_id can
  lead …
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-266
  - CWE-285
vendor: portabilis
product: i-educar
affected:
  - i-educar <= 2.10.0
published: '2026-02-06'
updated: '2026-09-15'
sourceUpdated: '2026-09-15T03:17:05.440'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-2015'
references:
  - url: >-
      https://github.com/ViniCastro2001/Security_Reports/tree/main/i-educar/BFLA-Final-Status-Import
    label: cna@vuldb.com
  - url: >-
      https://github.com/ViniCastro2001/Security_Reports/tree/main/i-educar/BFLA-Final-Status-Import#proof-of-concept-poc
    label: cna@vuldb.com
  - url: 'https://github.com/portabilis/i-educar/releases/tag/2.11.0'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-2015'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/743760'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/344597'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/344597/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-02-06T13:18:37.077094Z'
epss: 0.00307
epssPercentile: 0.23625
ingestedAt: '2026-09-15T03:19:45.415Z'
---

## Overview

A weakness has been identified in Portabilis i-Educar up to 2.10. Affected is an unknown function of the file FinalStatusImportService.php of the component Final Status Import. Executing a manipulation of the argument school_id can lead to improper authorization. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 2.11.0 is able to address this issue. Upgrading the affected component is advised. The vendor explains, that "[t]he reported attack vector was tested against the corrected code, and the previously described behavior could no longer be reproduced".

## Affected

- `i-educar <= 2.10.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
