CVE-2026-86672
Deferred Deferred - Pending Action

Information Disclosure in Ningzichun Student Management System

Vulnerability report for CVE-2026-86672, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-11

Assigner: VulDB

Description

A vulnerability has been found in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected is an unknown function of the file example.7z of the component Backup Handler. The manipulation leads to information disclosure. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-11
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ningzichun student_management_system to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the ningzichun Student Management System up to a specific commit hash. It is located in the Backup Handler component of the file example.7z. The issue allows an attacker to remotely access and disclose sensitive information due to improper handling of backups.

Impact Analysis

An attacker could exploit this vulnerability to gain unauthorized access to confidential student or system data. This may lead to privacy breaches, data leaks, or further attacks on the system if sensitive information is exposed.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA due to unauthorized data disclosure. GDPR requires protection of personal data, and HIPAA mandates safeguards for health information. A breach may result in legal penalties or loss of trust.

Mitigation Strategies

Since the vulnerability is in the Student Management System's Backup Handler and allows remote information disclosure, isolate the system from untrusted networks, disable backup features if not essential, and monitor for unusual data access patterns. Contact the vendor for patches as they have not responded yet.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86672. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart