Executive brief
WeenyGenius is a computer lab management system used by educational institutions to control and monitor student computers in classroom environments. CVE-2026-89176 allows unauthenticated attackers on the same network to impersonate students or teachers without any login credentials, enabling them to disrupt classes, take remote control of student systems, or manipulate classroom operations. This affects organizations running version 12.2.031 or earlier.
Technical details
CVE-2026-89176 is a missing authentication vulnerability in WeenyGenius that allows unauthenticated attackers on the same network to spoof student or teacher endpoints. The system lacks proper identity verification mechanisms for endpoint communication, enabling attackers to send network packets with forged identities. An attacker can impersonate a teacher workstation to send commands that cause student computers to establish connections to attacker-controlled systems, effectively granting remote control. Impersonating a student endpoint can disrupt classroom operations and learning management. The vulnerability requires network adjacency (same network segment) but no credentials or user interaction. A patch is available in version 12.3.033 and later.
Affected products
- Howyar Technologies WeenyGenius 12.2.031 and earlier
Timeline
- 2026-09-11: disclosed