Junglewise Threat Intelligence

CVE-2026-3111: Educativa Campus IDOR in profile photo endpoint

CVE-2026-3111 · Severity: info · CVSS 6.9 · Published 2026-03-16

Executive brief

Campus Educativa is an e-learning platform used by companies to manage and sell training courses. A security flaw allows anyone on the internet to access and download the profile photos of all registered users without logging in. This exposure could lead to privacy violations, identity impersonation, or targeted social engineering attacks against employees and students.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in the '/archivos/usuarios/[ID]/[username]/thumb_AAxAA.jpg' endpoint of Campus Educativa. The application fails to implement proper authorization checks, allowing unauthenticated remote attackers to access user profile images by guessing or brute-forcing the user ID and username in the URL path. This flaw enables the bulk collection of user imagery, which can be leveraged for facial recognition linking or doxxing. The vulnerability is addressed in version 14.05.00-159.

Affected products

  • Educativa Campus Educativa 14.05.00-35 up to (but not including) 14.05.00-159

Timeline

  • 2026-03-16: disclosed
  • 2026-03-16: advisory: Advisory published by INCIBE-CERT
  • 2026-03-16: patched: Fixed in version 14.05.00-159

References

Related threats