WeenyGenius, a computer lab management system by Howyar Technologies has a security flaw

Published September 11, 2026 CVE-2026-89178

WeenyGenius can make student computers try to connect to an attacker on the same network. The attacker does not need to log in first.

Severity
HighCVSS 3.1 · 8.8 · cert.org.tw
Fix
Fixed in 12.3.033
Affected versions
through 12.2.031
Weakness
CWE-940
Exploit likelihood
0.23% in 30 daysEPSS, higher than 14% of known flaws
Affects
WeenyGenius
Exploited
Not confirmedNo confirmation recorded
CISA SSVC
No known exploitationAutomatable: no · Technical impact: total
EU ID
EUVD-2026-76005ENISA vulnerability database

How it works

  • An unauthenticated attacker on the same network pretends to be the teacher workstation.
  • The attacker sends broadcast messages from that false source.
  • Student computers then attempt to establish a connection with the attacker.

What to do

Check the installed WeenyGenius version. Versions 12.2.031 and earlier are affected.

Update WeenyGenius to version 12.3.033 or later.

Technical details

CVE-2026-89178 is an origin validation flaw in WeenyGenius. An unauthenticated user on the same network can spoof the teacher workstation and send broadcast packets that make student computers attempt an attacker-controlled connection.

Severity breakdown

  • Attack vector Adjacent Needs access to the same local network
  • Attack complexity Low Low complexity under the assessed conditions
  • Privileges required None Attacker needs no account or login
  • User interaction None No victim action needed
  • Scope Unchanged Impact stays within the same security authority
  • Confidentiality impact High Sensitive data can be exposed with serious impact
  • Integrity impact High Protected data can be changed with serious impact
  • Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Open in FIRST.org calculator

References