CVE-2026-25876 - PlaciPy is Missing Authorization on Assessment Results Endpoint

CVE-2026-25876 - PlaciPy is Missing Authorization on Assessment Results Endpoint

CVE ID : CVE-2026-25876 Published : Feb. 9, 2026, 9:15 p.m. | 1 hour, 7 minutes ago Description : PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the backend/src/routes/results.routes.ts verify authentication but fails to enforce object-level authorization (ownership checks). For example, this can be used to return all results for an assessment. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
Feb. 9, 2026