CVE-2026-82621: Soarkey StudentManagement/学生信息管理系统 Administrative Servlet AdminDao.java AdminDao.doGet authorization
A weakness has been identified in Soarkey StudentManagement and 学生信息管理系统 up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. This impacts the function AdminDao.doGet of the file code/src/service/AdminDao.java of the component Administrative Servlet. Executing a manipulation of the argument action can lead to authorization bypass. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attack can be performed remotely by manipulating the action argument handled by AdminDao.doGet. No privileges or user interaction are indicated by the supplied severity vector.
Are systems likely to face active exploitation risk?
A public exploit is available, so the issue could be used in attacks. The supplied information also indicates low attack complexity and network reachability.
Is a fix or vendor response available?
The project was notified through an issue report but had not responded at the time of the report. No patched version or official mitigation is provided in the available data.