PT-2026-89799 · Howyar · Weenygenius
CVE-2026-89176
·
Published
2026-09-11
·
Updated
2026-09-11
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
A high severity missing authentication flaw in WeenyGenius allows unauthenticated attackers on the same network to spoof endpoints and gain remote control over student devices.
Key Points:
CVE-2026-89176 is a missing authentication vulnerability in WeenyGenius, a computer lab management system by Howyar Technologies. The flaw carries a CVSS score of 8.8 and allows any unauthenticated attacker on the local network to impersonate student or teacher endpoints. Impersonating a teacher endpoint can induce student computers to initiate connections, granting the attacker remote control over those devices. No specific affected versions are listed in the advisory, and no patch or public proof of concept was available at the time of publication.
The vulnerability stems from a complete lack of authentication in the endpoint communication layer of the WeenyGenius system. Because network traffic intended for endpoint management is not properly validated, an attacker who is already on the same network as the lab can easily spoof legitimate student or teacher stations. This lack of verification means the system accepts commands from the attacker as if they came from a trusted source within the classroom environment.
The impact ranges from simple disruption of classroom operations to more severe remote control of student computers. Specifically, when an attacker successfully impersonates a teacher endpoint, they can trigger student computers to initiate connections back to the attacker. This mechanism effectively hands over control of the student devices to the unauthenticated user. Since the advisory does not specify which versions are affected, organizations using WeenyGenius should verify their deployments to confirm exposure.
How are you currently segmenting your lab networks to prevent local attackers from reaching management systems?
Learn More: The Hacker Wire
Want to stay updated on the latest cyber threats?
👉 Subscribe to /r/PwnHub
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Weenygenius