CVE-2026-7491

8.1

Zyosoft · School App

Zyosoft School App contains an Insecure Direct Object Reference vulnerability allowing authenticated remote attackers to access and modify other users' data.

Executive summary

An authorization bypass vulnerability in the Zyosoft School App allows authenticated remote attackers to compromise user data confidentiality and integrity.

Vulnerability

This is an Insecure Direct Object Reference vulnerability mapped to CWE-639, involving authorization bypass through a user-controlled key, requiring low-level attacker authentication via the network vector.

Business impact

The exploitation of this vulnerability can result in widespread data exposure and unauthorized modification of sensitive user records across the application. With a CVSS score of 8.1 categorized as high severity, successful attacks undermine data privacy, potentially lead to regulatory non-compliance fines, and erode customer trust.

Remediation

Immediate Action: Update the Android version of School App to 1.1.62 or later, and the iOS version to 2.7.2 or later.

Proactive Monitoring: Review application access logs for unusual patterns of parameter manipulation associated with object retrieval and updates.

Compensating Controls: Implement strict server-side authorization checks and validation controls on API endpoints to verify that the requesting user owns the requested object.

Exploitation status

Public Exploit Available: False

Analyst recommendation

Given the high severity score and potential for large-scale data compromise, administrators should treat this advisory with urgency. Apply the vendor-supplied updates immediately to secure user records against unauthorized access.

Sources