Sceawere

Vulnerability Detail

CVE-2026-62101UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated Authentication Bypass in EduAdmin

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
8h ago
Vendor
Product
N/A
Attack Type
N/A
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Narrative and Response

Description

Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-09-17T14:17:14.977Z",
  "pubdate": "2026-09-17T14:17:14.977Z",
  "executiveSummary": "The vulnerability identified in EduAdmin Booking versions 5.4.2 and below constitutes a critical authentication bypass flaw.\nThis vulnerability allows an unauthenticated remote attacker to circumvent standard authentication protocols and gain unauthorized access to the application.\nThe flaw stems from improper validation of authentication credentials or session handling mechanisms within the application's authentication logic.\nSuccessful exploitation enables full unauthorized access to the system, potentially exposing sensitive administrative functions, booking data, and user information.\nDue to the nature of the vulnerability, no valid credentials are required for an attacker to compromise the integrity and confidentiality of the affected deployment.\nThe risk implication is severe, as it grants arbitrary control over administrative interfaces without needing to satisfy any pre-existing security requirements.\nThe vulnerability is accessible over the network, requiring only reachability to the application's authentication endpoint to facilitate an exploit.",
  "technicalDetails": "The vulnerability manifests as an Unauthenticated Broken Authentication flaw within EduAdmin Booking versions <= 5.4.2.\nThe root cause resides in the application's authentication handling logic, which fails to enforce strict authentication checks or improperly validates session identifiers, allowing for an bypass of the login procedure entirely.\nIn the standard authentication flow, the application is expected to verify user-supplied credentials against a backend database and issue a cryptographically secure session token.\nHowever, due to a flaw in the implementation of the authentication verification component, the system incorrectly trusts the request context or fails to validate the presence and validity of tokens under specific conditions.\nAn attacker can exploit this by interacting directly with sensitive authentication endpoints. By crafting a specific HTTP request that bypasses the login routine, the attacker forces the application to treat the incoming request as authenticated.\nThe attack flow typically involves identifying the specific endpoint responsible for session initialization and manipulating the request parameters or headers to deceive the application's logic into granting an authenticated session.\nBecause the application lacks adequate enforcement of server-side state validation, it assumes the session is valid, thereby escalating the attacker's privileges to that of an authenticated user, typically an administrator, based on the exposed session logic.\nThe post-exploitation impact allows an attacker to perform administrative actions, extract sensitive booking information, modify system configurations, or execute other functions normally restricted to authorized personnel.\nThe vulnerability is exposed over the network, and the exploit is platform-independent, requiring only basic HTTP traffic manipulation.\nThere are no complex requirements for successful exploitation, as the flaw resides within the fundamental authentication logic of the application, which is exposed to any remote user capable of reaching the web server."
}
CVE-2026-62101: Unauthenticated Authentication Bypass in EduAdmin (CRITICAL Severity, CVSS: 9.8) | Sceawere