CVE-2026-19853
Received Received - Intake

Missing Authentication in NewSiteServer Allows Unauthenticated Email Sending

Vulnerability report for CVE-2026-19853, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-24

Last updated on: 2026-08-24

Assigner: TWCERT/CC

Description

NewSiteServer (NSS) developed by CyberTutor has a Missing Authentication vulnerability. Unauthenticated remote attackers can exploit a specific functionality to send emails to anyone on behalf of the school.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-24
Last Modified
2026-08-24
Generated
2026-08-24
AI Q&A
2026-08-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
cybertutor newsiteserver to 2026-08-24 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

NewSiteServer (NSS) by CyberTutor has a Missing Authentication vulnerability. Unauthenticated remote attackers can exploit a specific function to send emails on behalf of a school without authorization.

Detection Guidance

Detection involves checking if NewSiteServer (NSS) is exposed to unauthenticated email-sending functionality. Inspect network traffic for SMTP requests originating from NSS without authentication headers. Verify server logs for unusual email activity or unauthorized SMTP connections. Use tools like Wireshark to monitor port 25 (SMTP) for suspicious outbound traffic from NSS.

Impact Analysis

This vulnerability allows attackers to send fraudulent emails pretending to be from your school. It could lead to phishing attacks, reputational damage, or unauthorized communications being sent under your school's name.

Compliance Impact

This vulnerability could potentially violate compliance with GDPR and HIPAA by enabling unauthorized email transmissions that may expose personal or sensitive data. Unauthenticated email sending on behalf of a school could lead to data breaches or unauthorized disclosures, which are key concerns under these regulations.

Mitigation Strategies

Contact the vendor CyberTutor for remediation as the vulnerability requires a patch from the developer. Monitor network traffic for unusual email activity originating from the NewSiteServer (NSS) system.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19853. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart