CVE-2026-89176: Howyar|WeenyGenius - Missing Authentication
WeenyGenius, a computer lab management system developed by Howyar Technologies, has a Missing Authentication vulnerability. Unauthenticated attackers on the same network can easily spoof student or teacher endpoints. Impersonating a student can disrupt normal classroom operations, whereas impersonating a teacher can induce student computers to initiate connections, thereby gaining remote control over the student endpoints.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Howyar|WeenyGeniusto a version that resolves this vulnerability.Fixed in 12.3.033
Event History
Frequently Asked Questions
Who is exposed to exploitation?
Systems running WeenyGenius are exposed to unauthenticated attackers on the same network. The attacker does not need prior credentials or user interaction.
What does an attacker need to do to exploit the issue?
The attacker needs network access to the same network as the WeenyGenius deployment and must spoof a student or teacher endpoint. No authentication is required.
What is the likely impact of spoofing each endpoint type?
Spoofing a student endpoint can disrupt normal classroom operations. Spoofing a teacher endpoint can cause student computers to initiate connections, allowing the attacker to gain remote control of student endpoints.