Junglewise Threat Intelligence

CVE-2026-5756: Data Recognition Corporation COS unauthenticated configuration modification

CVE-2026-5756 · Severity: high · CVSS 7.5 · Published 2026-04-14

Executive brief

Data Recognition Corporation's Central Office Services (COS), a platform used by schools to host and distribute educational testing content, contains a security flaw that allows unauthorized users on the same network to modify the server's configuration. An attacker could exploit this to redirect student test data to their own servers, intercept sensitive traffic, or shut down testing services entirely. This could lead to the loss of student records, privacy breaches, and significant disruption to academic assessments.

Technical details

A vulnerability exists in the /v0/configuration administrative endpoint of the DRC Central Office Services (COS) Content Hosting Component. The application uses a unified API router that fails to enforce authentication or origin validation for management functions. An unauthenticated attacker on the same network can submit malicious JSON payloads to this endpoint to overwrite the server's configuration file. This can be used to change storage destinations for test artifacts, inject a malicious HTTPS proxy for traffic interception, or cause a denial-of-service by providing malformed configuration data. The issue is resolved in Version 9.2.

Affected products

  • Data Recognition Corporation (DRC) Central Office Services - Content Hosting Component Versions prior to 9.2

Timeline

  • 2026-02-09: other: Vendor notified
  • 2026-04-14: disclosed: Initial CVE publication
  • 2026-04-23: advisory: CERT/CC vulnerability note published
  • 2026-05-21: patched: Vendor confirmed fix in Version 9.2

References