Threats Tagged 'cve-2026-25811'
View all threats tagged with 'cve-2026-25811'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-25811'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-25811 is a medium-severity authorization vulnerability in PlaciPy version 1.0.0, a placement management system for educational institutions. The application derives tenant identifiers solely from the user's email domain without validating domain ownership, enabling unauthorized cross-tenant data access. This flaw allows an attacker to access data belonging to other tenants by exploiting the weak domain-based tenant identification. The vulnerability does not require user interaction or authentication but does require low privileges. Although no known exploits are currently in the wild, the impact on confidentiality is significant, especially for institutions managing sensitive student placement data. European educational institutions using PlaciPy 1.0.0 are at risk, particularly in countries with high adoption of this software or large educational sectors. Join the discussion | CVE Database V5 | 02/09/2026, 21:00:38 UTC Added: 02/09/2026, 21:31:17 UTC |
Showing 1 to 1 of 1 result