Junglewise Threat Intelligence

CVE-2026-10167: OUSL-GROUP-BrinaryBrains School Student Management System auth bypass

CVE-2026-10167 · Severity: high · CVSS 7.3 · Published 2026-05-31

Technologies: OUSL-GROUP-BrinaryBrains School Student Management System. Vendors: OUSL-GROUP-BrinaryBrains.

Executive brief

A security flaw in the BrinaryBrains School Student Management System allows unauthorized individuals to bypass login security. This system is used to manage school operations, including student records and administrative tasks. By exploiting this weakness, an attacker can gain full access to the system as an administrator or teacher, potentially leading to the theft of sensitive student data or the disruption of school operations.

Technical details

An authentication bypass vulnerability exists in the `sign_auth_cookie` function within `application/controllers/Login.php` (part of `MY_Controller`). The application uses a hardcoded encryption key ('Signetbd') in `application/config/config.php` to generate HMAC-SHA256 signatures for the `school_auth` cookie. Because the key is static and publicly known, a remote, unauthenticated attacker can forge a valid `school_auth` cookie for any role (e.g., admin, teacher) and user ID. When the server processes this forged cookie via `restore_auth_session_from_cookie()`, it validates the signature against the hardcoded key and establishes a valid session, granting the attacker full access to the impersonated account. As of the advisory date, no patch has been released by the vendor.

Affected products

  • OUSL-GROUP-BrinaryBrains School Student Management System up to 1e70e5ad1125b86dca4ee086eb6bb121f17708b6

Timeline

  • 2026-05-04: disclosed: Issue reported to the project on GitHub
  • 2026-05-31: advisory: CVE published and NVD record created

References