CVE-2026-7491
8.1Zyosoft · School App
Zyosoft School App contains an Insecure Direct Object Reference vulnerability allowing authenticated remote attackers to access and modify other users' data.
Executive summary
An authorization bypass vulnerability in the Zyosoft School App allows authenticated remote attackers to compromise user data confidentiality and integrity.
Vulnerability
This is an Insecure Direct Object Reference vulnerability mapped to CWE-639, involving authorization bypass through a user-controlled key, requiring low-level attacker authentication via the network vector.
Business impact
The exploitation of this vulnerability can result in widespread data exposure and unauthorized modification of sensitive user records across the application. With a CVSS score of 8.1 categorized as high severity, successful attacks undermine data privacy, potentially lead to regulatory non-compliance fines, and erode customer trust.
Remediation
Immediate Action: Update the Android version of School App to 1.1.62 or later, and the iOS version to 2.7.2 or later.
Proactive Monitoring: Review application access logs for unusual patterns of parameter manipulation associated with object retrieval and updates.
Compensating Controls: Implement strict server-side authorization checks and validation controls on API endpoints to verify that the requesting user owns the requested object.
Exploitation status
Public Exploit Available: False
Analyst recommendation
Given the high severity score and potential for large-scale data compromise, administrators should treat this advisory with urgency. Apply the vendor-supplied updates immediately to secure user records against unauthorized access.