---
id: CVE-2026-97879
title: A security flaw has been discovered in zhistaredu StarTraining up to 3.8.1
summary: >-
  A security flaw has been discovered in zhistaredu StarTraining up to 3.8.1.
  The affected element is an unknown function of the file SecurityConfig.java of
  the component api-docs Endpoint. Performing a manipulation results in missing
  auth…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-287
  - CWE-306
vendor: zhistaredu
product: StarTraining
affected:
  - StarTraining 3.8.0
  - StarTraining 3.8.1
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T18:17:34.930'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-97879'
references:
  - url: >-
      https://github.com/ArrestX/startraining-advisories/blob/main/advisories/ST-VULN-003-swagger-api-docs-unauth.md
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-97879'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/913577'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/409900'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/409900/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-25T17:02:11.698235Z'
ingestedAt: '2026-09-25T17:13:14.018Z'
---

## Overview

A security flaw has been discovered in zhistaredu StarTraining up to 3.8.1. The affected element is an unknown function of the file SecurityConfig.java of the component api-docs Endpoint. Performing a manipulation results in missing authentication. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
