Junglewise Threat Intelligence

CVE-2026-19853: CyberTutor NewSiteServer missing authentication in email functionality

CVE-2026-19853 · Severity: medium · CVSS 5.3 · Published 2026-08-24

Executive brief

NewSiteServer is a web-based school management system used by educational institutions to manage campus information and communications. The vulnerability allows unauthenticated attackers to send emails on behalf of the school to anyone, potentially enabling credential harvesting, phishing campaigns, or reputation damage by impersonating school communications.

Technical details

The vulnerability is a missing authentication flaw in the email sending functionality of NewSiteServer. Unauthenticated remote attackers can directly access and exploit a specific email feature without requiring valid credentials, allowing them to send arbitrary emails that appear to originate from the school. The attack requires only network access to the affected service (no user interaction or authentication needed). This enables email spoofing and unauthorized communications, potentially facilitating social engineering attacks targeting students, parents, and staff. No patch availability information is currently available; organizations should contact CyberTutor for remediation.

Affected products

  • CyberTutor NewSiteServer

Timeline

  • 2026-08-24: disclosed

References