← Back to search

CVE-2026-62101

9.8 CRITICAL

Published 2026-09-17 · Updated 2026-09-17

AI risk analysis

Summary
The flaw is an unauthenticated broken authentication vulnerability in EduAdmin Booking versions 5.4.2 and earlier, allowing attackers to bypass authentication mechanisms and gain unauthorized access to the system.
Exploitability
Exploitation is relatively easy as it does not require authentication, and attackers can leverage this to gain full control over the system.
Blast radius
If exploited, the impact could be severe, potentially leading to data breaches, unauthorized access to administrative functions, and complete system compromise.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to EduAdmin Booking version 5.4.3 or later.
auth-bypasswebunauthenticated

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-288

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.