CVE-2026-97878: zhistaredu StarTraining Druid Console index.html anonymous missing authentication
A vulnerability was identified in zhistaredu StarTraining up to 3.8.1. Impacted is the function anonymous of the file /druid/index.html of the component Druid Console. Such manipulation leads to missing authentication. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed?
zhistaredu StarTraining installations up to version 3.8.1 with the Druid Console component are affected. The exposed endpoint is /druid/index.html.
Does exploitation require credentials or user interaction?
No. The vulnerability is remotely exploitable with no privileges or user interaction required.
How urgent is remediation?
Remediation should be prioritized because public exploit code is available and may be used. The vendor did not respond to the reported disclosure.
How can I check whether an installation is affected?
Identify StarTraining deployments at version 3.8.1 or earlier and determine whether the Druid Console endpoint at /druid/index.html is accessible without authentication.