CVE-2026-89179: Howyar|WeenyGenius - Missing Support for Integrity Check
WeenyGenius, a computer lab management system by Howyar Technologies, has a Missing Support for Integrity Check vulnerability. Unauthenticated attackers on the same network can intercept a student's connection packet and replay it, thereby forging the appearance that the student remains connected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WeenyGenius (Howyar Technologies)to a version that resolves this vulnerability.Fixed in 12.3.033
Event History
Frequently Asked Questions
Which environments are exposed to exploitation?
Systems are exposed when an unauthenticated attacker can access the same network as a student's WeenyGenius connection. The issue relies on intercepting and replaying that student's connection packet.
What access or privileges does an attacker need?
The attacker does not need authentication or prior privileges. They need to be on the same network and able to intercept the student's connection traffic.
What is the practical impact of a successful attack?
A successful replay can forge the appearance that a student remains connected. The provided information identifies an integrity impact, but does not describe confidentiality loss or service disruption.