Junglewise Threat Intelligence

CVE-2026-100876: CloudClassroom-PHP-Project authentication bypass in loginlinkstudent.php

CVE-2026-100876 · Severity: medium · CVSS 6.3 · Published 2026-09-27

Technologies: Mathurvishal CloudClassroom PHP Project. Vendors: Mathurvishal.

Executive brief

CloudClassroom-PHP-Project is a PHP-based classroom management application. A missing authentication vulnerability in the loginlinkstudent.php file allows attackers to manipulate the umail parameter and bypass login controls, potentially gaining unauthorized access to student accounts and educational data without valid credentials.

Technical details

The vulnerability exists in loginlinkstudent.php where the umail parameter is processed without proper authentication validation, allowing direct manipulation to bypass login checks. Remote exploitation is possible without authentication or user interaction required. An attacker can gain unauthorized access to student accounts and associated classroom data.

Affected products

  • mathurvishal CloudClassroom-PHP-Project up to commit 5dadec098bfbbf3300d60c3494db3fb95b66e7be

Timeline

  • 2026-09-27: disclosed
  • other: Exploit code made public; vendor did not respond to early disclosure notification

References

Related threats