CVE-2026-100879
Received Received - Intake

Remote Code Execution in StarTraining Application

Vulnerability report for CVE-2026-100879, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-27

Last updated on: 2026-09-27

Assigner: VulDB

Description

A security flaw has been discovered in zhistaredu StarTraining up to 3.8.1. This affects the function checkRoleAllowed of the file SysRoleServiceImpl.java of the component dataScope Endpoint. The manipulation results in missing authorization. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-27
Last Modified
2026-09-27
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zhistaredu startraining to 3.8.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a missing authorization flaw in zhistaredu StarTraining up to version 3.8.1. It exists in the checkRoleAllowed function of SysRoleServiceImpl.java within the dataScope Endpoint component. The issue allows remote attackers to bypass access controls due to improper role validation.

Detection Guidance

This vulnerability involves missing authorization in the zhistaredu StarTraining component up to 3.8.1. Detection requires checking for unauthorized access attempts or misconfigured role permissions in the SysRoleServiceImpl.java file. No specific commands are provided in the context.

Impact Analysis

An attacker could exploit this to access restricted data or perform unauthorized actions by sending crafted requests to the vulnerable endpoint. Since the exploit is public, the risk of active attacks is higher. The impact depends on the application's role-based access controls.

Compliance Impact

This vulnerability could lead to unauthorized data access, violating confidentiality requirements in GDPR and HIPAA. Organizations using this software may fail compliance audits if sensitive data is exposed due to missing authorization checks.

Mitigation Strategies

Immediately update zhistaredu StarTraining to the latest version beyond 3.8.1. If no update is available, restrict network access to the affected component SysRoleServiceImpl.java and disable the dataScope Endpoint. Monitor for unusual remote access attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-100879. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart