PT-2026-93125 · Tts-Be · Tts-Be

CVE-2026-88065

·

Published

2026-09-15

·

Updated

2026-09-16

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions tts-be versions prior to 2.1.0
Description Broken Access Control exists across several API endpoints, including '/api/student/{id}/photo' and '/api/course unit/{id}/exchange/metadata'. By chaining these unauthenticated endpoints, a remote attacker can utilize the backend as an open proxy to bypass authorization checks. This allows for the enumeration and extraction of sensitive Personally Identifiable Information (PII) from upstream university systems, including full names, student IDs, class schedules, and photos.
Recommendations Update to version 2.1.0. Restrict access to the '/api/student/{id}/photo' and '/api/course unit/{id}/exchange/metadata' endpoints to minimize the risk of exploitation.

Exploit

Fix

IDOR

Missing Authentication

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-88065
GHSA-FPFP-HR42-FVPM

Affected Products

Tts-Be