Junglewise Threat Intelligence

CVE-2026-82621: Soarkey StudentManagement authorization bypass in Administrative Servlet

CVE-2026-82621 · Severity: high · CVSS 7.3 · Published 2026-08-31

Technologies: Soarkey StudentManagement. Vendors: Soarkey.

Executive brief

Soarkey StudentManagement is a Java-based student information system used to manage departments, students, courses, and grades. The application contains an unauthenticated administrative servlet that processes sensitive operations without validating user identity or permissions, allowing any remote attacker to read all user credentials, create or delete departments, and modify academic records without logging in.

Technical details

The AdminDao servlet in the application processes administrative actions via an unauthenticated request parameter without enforcing any session validation, authentication checks, or authorization controls. The vulnerable doGet() method switches on an "action" parameter and dispatches to handlers (query_all_user, insert_department, delete_department, etc.) without verifying caller identity or role. Attackers can exploit this by sending direct HTTP requests to /AdminDao with crafted action parameters—for example, ?action=query_all_user returns all user credentials in plaintext, and ?action=insert_department allows creation of arbitrary departments. No authentication or session cookie is required to perform these operations. The issue was reported via GitHub issue #32 in July 2026 but the maintainer has not responded or patched the vulnerability. Patches are not yet available.

Affected products

  • Soarkey StudentManagement up to commit e08f7f1d5015af407aa4cca0ada3dea189b4937e

Timeline

  • 2026-07-16: disclosed: Vulnerability reported via GitHub issue #32
  • 2026-08-31: advisory: CVE-2026-82621 published

References

Related threats