CVE-2026-19784: francoisjacquet RosarioSIS Referrals.php DBUpdate authorization
A flaw has been found in francoisjacquet RosarioSIS up to 12.8. This affects the function DBUpdate of the file Discipline/Referrals.php. This manipulation causes authorization bypass. The attack may be initiated remotely. The exploit has been published and may be used. Upgrading to version 12.9 is able to mitigate this issue. Patch name: 04dd1a368ddf80ad7082baefa3c656e4e1825c76. It is suggested to upgrade the affected component.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
francoisjacquet RosarioSISto a version that resolves this vulnerability.Fixed in 12.9 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch 04dd1a368ddf80ad7082baefa3c656e4e1825c76 - Compensating control
Because the authorization bypass may be initiated remotely and an exploit is published, restrict network access to the RosarioSIS application endpoints that include Discipline/Referrals.php (e.g., via firewall/ACL) to trusted sources until the upgrade to 12.9 is applied.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19784?
CVE-2026-19784 has a medium severity rating of 4.3.
What software is affected by CVE-2026-19784?
CVE-2026-19784 affects francoisjacquet RosarioSIS versions up to 12.8.
What type of vulnerability is CVE-2026-19784?
CVE-2026-19784 is an authorization bypass vulnerability found in the DBUpdate function.
How do I fix CVE-2026-19784?
To fix CVE-2026-19784, upgrade to francoisjacquet RosarioSIS version 12.9 or later.
Can CVE-2026-19784 be exploited remotely?
Yes, CVE-2026-19784 can be exploited remotely.