---
id: CVE-2026-97877
title: A vulnerability was determined in zhistaredu StarTraining up to 3.8.1
summary: >-
  A vulnerability was determined in zhistaredu StarTraining up to 3.8.1. This
  issue affects the function UserLoginService.createToken of the file
  application.yml of the component JWT Token Handler. This manipulation of the
  argument user_id…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-255
  - CWE-259
vendor: zhistaredu
product: StarTraining
affected:
  - StarTraining 3.8.0
  - StarTraining 3.8.1
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T18:17:34.660'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-97877'
references:
  - url: >-
      https://github.com/ArrestX/startraining-advisories/blob/main/advisories/ST-VULN-001-jwt-hardcoded-secret-forge.md
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-97877'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/913575'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/409898'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/409898/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-25T17:21:24.486127Z'
ingestedAt: '2026-09-25T17:13:14.026Z'
---

## Overview

A vulnerability was determined in zhistaredu StarTraining up to 3.8.1. This issue affects the function UserLoginService.createToken of the file application.yml of the component JWT Token Handler. This manipulation of the argument user_id/company_id causes use of hard-coded password. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
