WeenyGenius, a computer lab management system developed by Howyar Technologies, has a Missing Authentication

Published September 11, 2026 CVE-2026-89176

WeenyGenius can let someone on the same network impersonate a teacher or student computer. Impersonating a teacher can give that person remote control of student computers.

Severity
HighCVSS 3.1 · 8.8 · cert.org.tw
Fix
Fixed in 12.3.033
Affected versions
through 12.2.031
Weakness
CWE-306Missing Authentication for Critical Function
Exploit likelihood
0.25% in 30 daysEPSS, higher than 16% of known flaws
Affects
WeenyGenius
Exploited
Not confirmedNo confirmation recorded
CISA SSVC
No known exploitationAutomatable: no · Technical impact: total
EU ID
EUVD-2026-76003ENISA vulnerability database

How it works

  • An attacker on the same network can impersonate a student or teacher computer without authentication.
  • Impersonating a student can disrupt classroom operations.
  • Impersonating a teacher can make student computers initiate connections, giving the attacker remote control.

What to do

Check the WeenyGenius version installed on each lab system. Versions 12.2.031 and earlier are affected.

Update WeenyGenius to version 12.3.033 or later.

Technical details

CVE-2026-89176 is a missing-authentication flaw in WeenyGenius. An unauthenticated attacker on the same network can spoof student or teacher endpoints without user interaction, with potential confidentiality, integrity, and availability impacts.

Severity breakdown

  • Attack vector Adjacent Needs access to the same local network
  • Attack complexity Low Low complexity under the assessed conditions
  • Privileges required None Attacker needs no account or login
  • User interaction None No victim action needed
  • Scope Unchanged Impact stays within the same security authority
  • Confidentiality impact High Sensitive data can be exposed with serious impact
  • Integrity impact High Protected data can be changed with serious impact
  • Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Open in FIRST.org calculator