Junglewise Threat Intelligence

CVE-2026-76999: SourceCodester CET Automated Grading System authorization bypass in add_grade

CVE-2026-76999 · Severity: medium · CVSS 6.3 · Published 2026-08-20

Technologies: SourceCodester CET Automated Grading System with AI Predictive Analytics. Vendors: SourceCodester.

Executive brief

SourceCodester CET Automated Grading System with AI Predictive Analytics is an online education platform used for automated student assessment and grade management. A vulnerability in the grade-addition function allows an attacker to manipulate student ID parameters remotely, potentially granting unauthorized access to modify grades for students they should not have permission to edit, compromising academic integrity and student records.

Technical details

The vulnerability is an improper authorization flaw in the add_grade function within /index.php of SourceCodester CET Automated Grading System version 1.0. An attacker can perform parameter manipulation on the student_id argument to bypass authorization checks, allowing them to perform unauthorized grade modifications. The attack requires network access to the application but does not appear to require prior authentication or complex preconditions. A successful exploit enables an attacker to modify academic records for arbitrary students, directly impacting data integrity. Patching information has not been confirmed as of the advisory date.

Affected products

  • SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0

Timeline

  • 2026-08-20: disclosed

References

Related threats