---
id: CVE-2026-86672
title: >-
  A vulnerability has been found in ningzichun Student Management System up to
  98760f5711cf6dc8b4adca53a9e207ca49b02ebf
summary: >-
  A vulnerability has been found in ningzichun Student Management System up to
  98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected is an unknown function of
  the file example.7z of the component Backup Handler. The manipulation leads to
  info…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-200
  - CWE-284
vendor: ningzichun
product: Student Management System
affected:
  - student_management_system 98760f5711cf6dc8b4adca53a9e207ca49b02ebf
published: '2026-09-08'
updated: '2026-09-11'
sourceUpdated: '2026-09-11T21:17:48.257'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86672'
references:
  - url: 'https://github.com/ningzichun/student-management-system/issues/14'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-86672'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/908930'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/399762'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/399762/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-11T20:53:02.003526Z'
epss: 0.00286
epssPercentile: 0.21408
ingestedAt: '2026-09-08T19:08:49.634Z'
---

## Overview

A vulnerability has been found in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected is an unknown function of the file example.7z of the component Backup Handler. The manipulation leads to information disclosure. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
