WeenyGenius, a computer lab management system developed by Howyar Technologies, has a Missing Authentication
WeenyGenius can let someone on the same network impersonate a teacher or student computer. Impersonating a teacher can give that person remote control of student computers.
- Severity
- HighCVSS 3.1 · 8.8 · cert.org.tw
- Fix
- Fixed in 12.3.033
- Affected versions
- through 12.2.031
- Weakness
- CWE-306Missing Authentication for Critical Function
- Exploit likelihood
- 0.25% in 30 daysEPSS, higher than 16% of known flaws
- Affects
- WeenyGenius
- Exploited
- Not confirmedNo confirmation recorded
- CISA SSVC
- No known exploitationAutomatable: no · Technical impact: total
- EU ID
- EUVD-2026-76003ENISA vulnerability database
How it works
- An attacker on the same network can impersonate a student or teacher computer without authentication.
- Impersonating a student can disrupt classroom operations.
- Impersonating a teacher can make student computers initiate connections, giving the attacker remote control.
What to do
Check the WeenyGenius version installed on each lab system. Versions 12.2.031 and earlier are affected.
Update WeenyGenius to version 12.3.033 or later.
Technical details
CVE-2026-89176 is a missing-authentication flaw in WeenyGenius. An unauthenticated attacker on the same network can spoof student or teacher endpoints without user interaction, with potential confidentiality, integrity, and availability impacts.
Severity breakdown
- Attack vector Adjacent Needs access to the same local network
- Attack complexity Low Low complexity under the assessed conditions
- Privileges required None Attacker needs no account or login
- User interaction None No victim action needed
- Scope Unchanged Impact stays within the same security authority
- Confidentiality impact High Sensitive data can be exposed with serious impact
- Integrity impact High Protected data can be changed with serious impact
- Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Open in FIRST.org calculatorReferences
- cve.org · CVERecord vdb entry
- cvefeed.io · CVE-2026-89176 third party advisory vdb entry
- euvd.enisa.europa.eu · EUVD-2026-76003 vdb entry
- cveawg.mitre.org · CVE-2026-89176
- twcert.org.tw · cp-139-11200-ffc3c-2.html third-party-advisory NVD
- twcert.org.tw · cp-132-11201-658c0-1.html third-party-advisory NVD