Junglewise Threat Intelligence

CVE-2026-14608: SourceCodester CET Automated Grading System authorization bypass in view_student

CVE-2026-14608 · Severity: medium · CVSS 4.3 · Published 2026-07-03

Technologies: SourceCodester CET Automated Grading System with AI Predictive Analytics. Vendors: SourceCodester.

Executive brief

A security vulnerability exists in the SourceCodester CET Automated Grading System, a platform used for academic grading and student data management. An attacker can bypass authorization controls to view student records they are not permitted to see. This could lead to the unauthorized exposure of sensitive student information and academic data.

Technical details

An authorization bypass vulnerability (CWE-639/CWE-285) exists in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. The flaw is located in the POST handler of the /index.php?action=view_student endpoint. By manipulating the 'ID' argument, a remote authenticated attacker can bypass intended access controls to view student data belonging to other users. The exploit has been disclosed publicly, and the vulnerability is confirmed to be remotely exploitable with low privileges.

Affected products

  • SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0

Timeline

  • 2026-07-03: advisory: NVD publication date
  • 2026-07-03: disclosed: Public exploit availability reported by VulDB

References

Related threats