CVE-2026-82698
CVE-2026-82698 is a medium-severity vulnerability with a CVSS 3.x base score of 5.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-1393.
Key facts
- Severity: Medium (CVSS 3.x base score 5.3)
- CVSS v2: 5.0
- CVSS v4: 5.5
- EPSS exploit prediction: 1% (43rd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-1393
- Published:
- Last modified:
Description
A vulnerability was detected in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. This affects an unknown function of the file aca.sql. Performing a manipulation results in use of default password. Remote exploitation of the attack is possible. The exploit is now public and may be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The project was informed of the problem early through an issue report but has not responded yet.
Frequently asked questions
- What is CVE-2026-82698?
- A vulnerability was detected in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. This affects an unknown function of the file aca.sql. Performing a manipulation results in use of default password. Remote exploitation of the attack is possible. The exploit is now public and may be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The project was informed of the problem early through an issue report but has not responded yet.
- How severe is CVE-2026-82698?
- CVE-2026-82698 has a CVSS 3.x base score of 5.3, rated medium severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is low, integrity none, and availability none.
- Is CVE-2026-82698 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (43rd percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-82698?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-82698 published?
- CVE-2026-82698 was published on 2026-08-31.
References
- https://github.com/sambitraj/STUDENT-MANAGEMENT-SYSTEM/
- https://github.com/sambitraj/STUDENT-MANAGEMENT-SYSTEM/issues/7
- https://vuldb.com/cve/CVE-2026-82698
- https://vuldb.com/submit/894305
- https://vuldb.com/vuln/397186
- https://vuldb.com/vuln/397186/cti
Other CWE-1393 vulnerabilities
- CVE-2025-26701 — Critical (CVSS 10.0): An issue was discovered in Percona PMM Server (OVA) before 3.0.0-1.ova. The default service account credentials can…
- CVE-2024-51555 — Critical (CVSS 10.0): Default Credentail vulnerabilities allows access to an Aspect device using publicly available default credentials since…
- CVE-2026-69657 — Critical (CVSS 9.8): XING CPTrans-ME-X contains a Use of Default Password (CWE-1393). Anyone with the knowledge of the credential may log in…
- CVE-2026-5269 — Critical (CVSS 9.8): In Ciena's Navigator Network Control Suite (NCS) and Manage Control Plan (MCP), there are hidden system accounts used…
- CVE-2026-35075 — Critical (CVSS 9.8): An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full…
- CVE-2026-33784 — Critical (CVSS 9.8): A Use of Default Password vulnerability in the Juniper Networks Support Insights (JSI) Virtual Lightweight…