CVE-2026-97877High· 7.3▾ MidnightPoC availableA vulnerability was determined in zhistaredu StarTraining up to 3.8.1. This issue affects the function UserLoginService.createToken of the file application.yml of the component JWT Token Handler. This manipulation of the argument user_id…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 40.2 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Exploit / PoC code exists
A vulnerability was determined in zhistaredu StarTraining up to 3.8.1. This issue affects the function UserLoginService.createToken of the file application.yml of the component JWT Token Handler. This manipulation of the argument user_id/company_id causes use of hard-coded password. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-97878High· 7.3A vulnerability was identified in zhistaredu StarTraining up to 3.8.1
CVE-2026-97879Medium· 5.3A security flaw has been discovered in zhistaredu StarTraining up to 3.8.1
CVE-2025-6139Low· 3.9A vulnerability, which was classified as problematic, has been found in TOTOLINK T10 4.1.8cu.5207
CVE-2026-96548Medium· 5.6A flaw has been found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8
CVE-2026-90509High· 7.3A weakness has been identified in dromara orion-visor up to 2.5.7
CVE-2026-71809High· 8.1Authentication Bypass via Hardcoded Master Verification Code vulnerability in Siam Ordering (siam-server) 1.0.0 allows remote unauthenticated attackers to log in as any user, merchant, or administrator.