CVE-2026-89176
Received Received - Intake

Missing Authentication in WeenyGenius Lab Management System

Vulnerability report for CVE-2026-89176, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: TWCERT/CC

Description

WeenyGenius, a computer lab management system developed by Howyar Technologies, has a Missing Authentication vulnerability. Unauthenticated attackers on the same network can easily spoof student or teacher endpoints. Impersonating a student can disrupt normal classroom operations, whereas impersonating a teacher can induce student computers to initiate connections, thereby gaining remote control over the student endpoints.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-09-11
AI Q&A
2026-09-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
howyar_technologies weenygenius to 12.3.033 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-89176 is a Missing Authentication vulnerability in WeenyGenius, a computer lab management system by Howyar Technologies. Unauthenticated attackers on the same network can impersonate students or teachers, disrupting classroom operations or gaining remote control over student computers.

Detection Guidance

Detecting CVE-2026-89176 requires monitoring network traffic for unauthorized impersonation attempts. Check for unusual connections from unknown endpoints mimicking student or teacher devices. Use packet capture tools like Wireshark to inspect ZMTP protocol traffic for null authentication or spoofed broadcasts. Verify WeenyGenius versions are updated to 12.3.033 or later to confirm patch status.

Impact Analysis

Impersonating a student can disrupt normal classroom operations. Impersonating a teacher can trick student computers into initiating connections, allowing attackers to gain remote control over those endpoints.

Compliance Impact

The vulnerability allows unauthenticated attackers to impersonate students or teachers, disrupt classroom operations, or gain remote control over student computers. This could lead to unauthorized access to sensitive data, violating confidentiality requirements under GDPR and HIPAA. Unauthorized access risks data breaches, which are non-compliant with these regulations.

Mitigation Strategies

Update WeenyGenius to version 12.3.033 or later to resolve the missing authentication vulnerability. Ensure the update is applied to all affected systems to prevent unauthenticated attackers from impersonating users or gaining control over student endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89176. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart