CVE-2026-82621
7.3Soarkey · StudentManagement
An unauthenticated authorization bypass in the AdminDao servlet of Soarkey StudentManagement allows remote attackers to execute administrative functions without valid credentials.
Executive summary
A critical authorization bypass vulnerability in Soarkey StudentManagement allows unauthenticated remote attackers to perform full administrative operations, including data modification and sensitive user disclosure.
Vulnerability
The application fails to perform identity or role validation within the AdminDao servlet. An unauthenticated attacker can manipulate the action request parameter to trigger privileged administrative methods, such as user querying or department modification.
Business impact
Successful exploitation grants an unauthenticated attacker full control over the application data, leading to the exposure of sensitive user credentials and the unauthorized modification of academic records. Given the high CVSS score of 7.3, this vulnerability presents a significant risk to data integrity and system confidentiality. Unauthorized administrative access can result in severe reputational damage and the total compromise of stored student and staff information.
Remediation
Immediate Action: As no official patch is currently available, administrators should immediately restrict network access to the /AdminDao endpoint and disable the application if it is exposed to untrusted networks.
Proactive Monitoring: Review web access logs for anomalous requests to the /AdminDao endpoint, specifically monitoring for unexpected action parameters such as query_all_user or delete_department.
Compensating Controls: Deploy a Web Application Firewall (WAF) to block unauthorized requests to the /AdminDao servlet and enforce strict access control policies at the network or reverse proxy level.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists as detailed in the project's GitHub issue tracker (Issue #32).
Analyst recommendation
The absence of an official vendor patch necessitates immediate manual intervention to secure the environment. Administrators must treat this as a high-priority risk and implement strict perimeter controls to prevent unauthenticated access to the vulnerable servlet, as the lack of authentication checks allows for trivial exploitation by any remote user.
Sources
Originally found and disclosed by soulinda (VulDB User), with VulDB CNA Team (coordinator), per the CVE Program record.
- VDB-397121 | Soarkey StudentManagement/学生信息管理系统 Administrative Servlet AdminDao.java AdminDao.doGet authorization Vulnerability database entry
- VDB-397121 | CTI Indicators (IOB, IOC, IOA)
- CVE-2026-82621 | CVE Analysis and Report Third-party advisory
- Submit #893104 | Soarkey StudentManagement e08f7f1d5015af407aa4cca0ada3dea189b4937e Authorization Bypass Third-party advisory
- Exploit / PoC
- github.com