CVE-2026-88065
Deferred Deferred - Pending Action

BaseFortify

Vulnerability report for CVE-2026-88065, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-30

Assigner: GitHub, Inc.

Description

`tts-be` is a backend for a timetable selector that aims to help students better choose their class schedules. Versions prior to 2.1.0 have a Broken Access Control vulnerability across several API endpoints (such as `/api/student/{id}/photo` and `/api/course_unit/{id}/exchange/metadata`). By chaining these unauthenticated endpoints, a remote attacker can use the backend as an open proxy to bypass authorization checks, allowing for the enumeration and extraction of sensitive Personally Identifiable Information (PII) from upstream university systems. The exposed data includes full names, student IDs, class schedules, and photos. This issue was fixed in version 2.1.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-30
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-05
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
NIAEFEUP tts-be < 2.1.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The vulnerability is a Broken Access Control issue in the tts-be timetable selector backend. Versions before 2.1.0 allow unauthenticated access to several API endpoints. By chaining these endpoints, attackers can bypass authorization checks and use the system as an open proxy to extract sensitive PII from connected university systems.

Detection Guidance

Check for unauthenticated access to endpoints like /api/student/{id}/photo or /api/course_unit/{id}/exchange/metadata. Verify if these endpoints return sensitive PII without proper authorization. Inspect network traffic for unusual proxy-like behavior or unauthorized data exfiltration.

Impact Analysis

Attackers could access and steal personal data including full names, student IDs, class schedules, and photos. This could lead to identity theft, privacy violations, or unauthorized access to academic records. The impact depends on the sensitivity of data exposed in your university system.

Compliance Impact

This vulnerability likely violates GDPR due to unauthorized processing of personal data and HIPAA if student health or biometric data is exposed. Organizations could face fines for failing to protect sensitive information under these regulations.

Mitigation Strategies

Upgrade to version 2.1.0 or later immediately. Ensure all API endpoints enforce strict authentication and authorization checks. Review and restrict access to sensitive endpoints to prevent unauthorized enumeration of PII.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-88065. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart