Zhistaredu · Startraining · CVE-2026-97878
**Name of the Vulnerable Software and Affected Versions**
zhistaredu StarTraining versions prior to 3.8.2
**Description**
A remote issue exists in the Druid Console component within the `/druid/index.html` file. The `anonymous()` function is susceptible to manipulation, which allows an attacker to bypass authentication requirements.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, restrict access to the `/druid/index.html` file to minimize the risk of exploitation.