Junglewise Threat Intelligence

CVE-2026-10169: BrinaryBrains School Student Management System weak password recovery

CVE-2026-10169 · Severity: low · CVSS 3.7 · Published 2026-05-31

Technologies: BrinaryBrains School Student Management System.

Executive brief

The BrinaryBrains School Student Management System, used for managing educational records, contains a flaw in its password recovery process. An attacker can exploit this to identify valid user email addresses and forcibly reset passwords for any account without authorization. This can lead to legitimate users being locked out of their accounts and potential disruption of school administrative operations.

Technical details

A business logic vulnerability exists in the 'ajax_forgot_password' function within 'application/controllers/Login.php'. The endpoint processes POST requests containing an email address and immediately updates the database with a new, randomly generated password without requiring a reset token, CAPTCHA, or secondary verification. Furthermore, the application returns different HTTP responses (Success vs. 500 Internal Server Error) based on whether the email exists, enabling account enumeration. An attacker can remotely trigger these resets to cause a denial-of-service for specific users. As of the advisory date, no patch has been released by the vendor.

Affected products

  • BrinaryBrains School Student Management System up to 1e70e5ad1125b86dca4ee086eb6bb121f17708b6

Timeline

  • 2026-05-05: disclosed: Issue reported to the project maintainers on GitHub.
  • 2026-05-31: advisory: CVE published via VulDB/NVD.

References