CVE-2026-19853: CyberTutor|NewSiteServer (NSS) - Missing Authentication
Published Aug 24, 2026
·Updated
NewSiteServer (NSS) developed by CyberTutor has a Missing Authentication vulnerability. Unauthenticated remote attackers can exploit a specific functionality to send emails to anyone on behalf of the school.
Affected Software
1 affected component
CyberTutor NewSiteServer (NSS)
Event History
Aug 24, 2026
CVE Published
via MITRE·03:30 AM
Data Sourced
via MITRE·03:30 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:16 AM
DescriptionSeverityWeakness
Mar 23, 58615
Event
via NVD·05:55 AM
Frequently Asked Questions
1
What can an unauthenticated attacker do if this is exploited?
An unauthenticated remote attacker can use the affected functionality to send emails to arbitrary recipients while impersonating the school.
2
Does exploitation require credentials or user interaction?
No. The reported vector is network-accessible, requires no privileges, and does not require user interaction.