Sceawere

Vulnerability Detail

CVE-2026-89176UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

WeenyGenius Missing Authentication Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
2h ago
Vendor
Howyar
Product
WeenyGenius
Attack Type
CWE-306 Missing Authentication for Critical Function
Vector String
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

WeenyGenius, a computer lab management system developed by Howyar Technologies, has a Missing Authentication vulnerability. Unauthenticated attackers on the same network can easily spoof student or teacher endpoints. Impersonating a student can disrupt normal classroom operations, whereas impersonating a teacher can induce student computers to initiate connections, thereby gaining remote control over the student endpoints.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-09-11T08:16:48.677Z",
  "pubdate": "2026-09-11T08:16:48.677Z",
  "executiveSummary": "The computer lab management system WeenyGenius, developed by Howyar Technologies, contains a critical missing authentication vulnerability. This flaw allows unauthenticated remote attackers positioned on the same local network to perform unauthorized identity spoofing of both student and teacher endpoints.\nThe vulnerability stems from the system's failure to enforce secure authentication mechanisms for communicating endpoints. By exploiting this oversight, an attacker can masquerade as a legitimate user, leading to significant disruption of classroom operations or unauthorized remote control of student workstations.\nThe impact of this vulnerability is severe, as it facilitates full unauthorized administrative control over client endpoints within the lab environment. Because the attack vector requires only network adjacency, the barrier to entry for exploitation is low. Organizations utilizing WeenyGenius are at risk of complete endpoint compromise, data leakage, and loss of instructional integrity, necessitating immediate network-level defensive interventions.",
  "technicalDetails": "The root cause of this vulnerability is the absence of a mandatory, cryptographically secure authentication handshake between the WeenyGenius server and its connected endpoints. The communication protocol lacks validation logic, allowing any device on the network segment to emit commands that the management server accepts as legitimate instructions originating from a trusted endpoint.\nThe exploitation process involves the attacker utilizing packet crafting or endpoint impersonation techniques to intercept or inject traffic within the local area network. By analyzing the traffic patterns of the WeenyGenius management protocol, an attacker can identify the specific data structures and operational commands used by the system to manage client sessions.\nTo initiate an attack, the adversary first performs network reconnaissance to identify active WeenyGenius components. Once identified, the attacker crafts a malicious packet payload that mimics the standard handshake or command structure used by teacher endpoints. Because the system fails to verify the source identity via pre-shared keys, digital certificates, or session tokens, the management system processes the spoofed instructions as authentic.\nIf the attacker impersonates a teacher endpoint, the system automatically elevates the attacker's commands to administrative status. The payload typically involves issuing a remote command to student workstations, such as instructing them to connect to an attacker-controlled listener or to execute arbitrary system commands. This mechanism effectively bypasses all access control lists (ACLs) and endpoint security policies enforced by the management console.\nPost-exploitation, the attacker gains persistent remote control over affected student workstations. This includes the ability to exfiltrate sensitive files, install additional malicious software, or monitor classroom activity through screen-scraping and remote shell access. The lack of mutual authentication ensures that the endpoints have no mechanism to verify the legitimacy of the server-side requests triggered by the spoofed teacher commands, creating a circular trust failure that compromises the entire lab architecture."
}
CVE-2026-89176: WeenyGenius Missing Authentication Vulnerability (HIGH Severity, CVSS: 8.8) | Sceawere