PT-2026-89799 · Howyar · Weenygenius

CVE-2026-89176

·

Published

2026-09-11

·

Updated

2026-09-11

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
A high severity missing authentication flaw in WeenyGenius allows unauthenticated attackers on the same network to spoof endpoints and gain remote control over student devices.
Key Points:
CVE-2026-89176 is a missing authentication vulnerability in WeenyGenius, a computer lab management system by Howyar Technologies. The flaw carries a CVSS score of 8.8 and allows any unauthenticated attacker on the local network to impersonate student or teacher endpoints. Impersonating a teacher endpoint can induce student computers to initiate connections, granting the attacker remote control over those devices. No specific affected versions are listed in the advisory, and no patch or public proof of concept was available at the time of publication.
The vulnerability stems from a complete lack of authentication in the endpoint communication layer of the WeenyGenius system. Because network traffic intended for endpoint management is not properly validated, an attacker who is already on the same network as the lab can easily spoof legitimate student or teacher stations. This lack of verification means the system accepts commands from the attacker as if they came from a trusted source within the classroom environment.
The impact ranges from simple disruption of classroom operations to more severe remote control of student computers. Specifically, when an attacker successfully impersonates a teacher endpoint, they can trigger student computers to initiate connections back to the attacker. This mechanism effectively hands over control of the student devices to the unauthenticated user. Since the advisory does not specify which versions are affected, organizations using WeenyGenius should verify their deployments to confirm exposure.
How are you currently segmenting your lab networks to prevent local attackers from reaching management systems?
Learn More: The Hacker Wire
Want to stay updated on the latest cyber threats?
👉 Subscribe to /r/PwnHub

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-89176

Affected Products

Weenygenius