Junglewise Threat Intelligence

CVE-2026-34906: Simple SA Wirtualna Uczelnia SSTI in redirectToUrl endpoint

CVE-2026-34906 · Severity: info · CVSS 9.3 · Published 2026-06-02

Executive brief

Wirtualna Uczelnia is a web portal used by universities to manage student records, grades, and academic schedules. A critical security flaw allows an unauthenticated attacker to remotely take control of the server hosting this portal. This could lead to the theft of sensitive student data, disruption of academic operations, or the deployment of ransomware within the university's network.

Technical details

A Server-Side Template Injection (SSTI) vulnerability exists in the Wirtualna Uczelnia academic portal. The flaw is located in the 'redirectToUrl' endpoint and specifically affects the 'redirectUrlParameter' parameter due to insufficient input validation. An unauthenticated remote attacker can inject arbitrary template expressions that are subsequently executed by the server's template engine. Successful exploitation allows for Remote Code Execution (RCE), enabling the attacker to run system commands or establish a reverse shell. The vulnerability is tracked as CVE-2026-34906 and affects all versions up to and including wu#2016.437.295#0#20260327_105545.

Affected products

  • Simple SA Wirtualna Uczelnia Up to and including wu#2016.437.295#0#20260327_105545

Timeline

  • 2026-06-02: advisory: Advisory published by CERT.PL
  • 2026-06-02: disclosed: CVE-2026-34906 published to NVD dataset

References

Related threats