Sceawere

Vulnerability Detail

CVE-2026-100879UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Missing Authorization in StarTraining

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
11h ago
Vendor
zhistaredu
Product
StarTraining
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

A security flaw has been discovered in zhistaredu StarTraining up to 3.8.1. This affects the function checkRoleAllowed of the file SysRoleServiceImpl.java of the component dataScope Endpoint. The manipulation results in missing authorization. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-09-27T21:17:01.283Z",
  "pubdate": "2026-09-27T21:17:01.283Z",
  "executiveSummary": "A critical security flaw has been identified in the dataScope component of zhistaredu StarTraining, affecting all versions up to and including 3.8.1.\nThe vulnerability is classified as a missing authorization issue, specifically residing within the checkRoleAllowed function of the SysRoleServiceImpl.java file.\nThis flaw enables unauthorized remote actors to bypass security controls, potentially granting them access to functions or data scopes restricted to privileged roles.\nThe risk is significantly amplified due to the public availability of exploit code, which may be weaponized by malicious actors against vulnerable installations.\nGiven that the vendor has not responded to disclosure attempts, the vulnerability remains unpatched in the affected versions, necessitating immediate defensive action by system administrators.\nThe attack is executable remotely and does not require pre-existing authentication, thereby exposing the application to a broad attack surface.",
  "technicalDetails": "The vulnerability originates in the checkRoleAllowed function located within the SysRoleServiceImpl.java source file, which serves as a critical component of the dataScope endpoint.\nThe root cause is a failure to properly implement authorization logic within the function responsible for role validation. The application does not correctly enforce access control checks when interacting with the dataScope endpoint, allowing users to bypass intended security constraints.\nThe exploitation process involves an unauthenticated remote attacker sending specifically crafted requests to the dataScope endpoint. Because the checkRoleAllowed method is improperly implemented, it fails to evaluate the session or user privileges against the requested operation, resulting in an authorization bypass.\nBy manipulating parameters within the request, an attacker can trick the system into performing unauthorized data scope actions, effectively escalating their access to restricted system functionality or sensitive data repositories.\nThe exposure is network-based, meaning any host with connectivity to the application's dataScope interface can attempt to trigger the vulnerability. The lack of robust authorization checks during the call flow allows the input to pass through validation, where the system then proceeds to execute the logic as if the user had sufficient permissions.\nThe post-exploitation impact includes the potential for unauthorized data access, modification, or the illicit execution of administrative tasks that should otherwise be restricted based on role-based access control (RBAC) policies. Since the vendor has provided no official patch, the system remains in a perpetual state of vulnerability, and the public release of exploitation scripts means that automated scanning and exploitation are likely occurrences."
}
CVE-2026-100879: Missing Authorization in StarTraining (MEDIUM Severity, CVSS: 4.3) | Sceawere