Zhistaredu · Startraining · CVE-2026-100879
**Name of the Vulnerable Software and Affected Versions**
zhistaredu StarTraining versions prior to 3.8.2
**Description**
A remote security flaw exists in the `dataScope` endpoint within the `SysRoleServiceImpl.java` file. The issue resides in the `checkRoleAllowed()` function, where improper manipulation can lead to missing authorization, allowing unauthorized access to restricted functionality.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, restrict access to the `dataScope` endpoint to minimize the risk of exploitation.