Junglewise Threat Intelligence

CVE-2026-12529: SourceCodester CET Automated Grading System access control bypass

CVE-2026-12529 · Severity: high · CVSS 7.3 · Published 2026-06-17

Technologies: SourceCodester CET Automated Grading System with AI Predictive Analytics. Vendors: SourceCodester.

Executive brief

A security vulnerability exists in the SourceCodester CET Automated Grading System, a software platform used for academic grading and analytics. The flaw is located in the student self-registration component, where improper access controls allow unauthorized individuals to bypass security restrictions. This could lead to unauthorized access to the system, potentially impacting the integrity of student data or grading operations.

Technical details

An improper access control vulnerability (CWE-284/CWE-266) exists in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. The flaw is located within the Student Self-Registration Endpoint in the /index.php file. A remote, unauthenticated attacker can exploit this vulnerability by manipulating requests to the registration component, leading to unauthorized access or incorrect privilege assignment. The attack can be executed over the network without user interaction. As of the advisory date, no specific patch or mitigation has been confirmed.

Affected products

  • SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats