๐Ÿ” CVE Alert

CVE-2026-97879

MEDIUM 5.3

zhistaredu StarTraining api-docs Endpoint SecurityConfig.java missing authentication

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

A security flaw has been discovered in zhistaredu StarTraining up to 3.8.1. The affected element is an unknown function of the file SecurityConfig.java of the component api-docs Endpoint. Performing a manipulation results in missing authentication. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CWE CWE-306 CWE-287
Vendor zhistaredu
Product startraining
Published Sep 25, 2026
Last Updated Sep 25, 2026
Stay Ahead of the Next One

Get instant alerts for zhistaredu startraining

Be the first to know when new medium vulnerabilities affecting zhistaredu startraining are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

zhistaredu / StarTraining
3.8.0 3.8.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/409900 vuldb.com: https://vuldb.com/vuln/409900/cti vuldb.com: https://vuldb.com/cve/CVE-2026-97879 vuldb.com: https://vuldb.com/submit/913577 github.com: https://github.com/ArrestX/startraining-advisories/blob/main/advisories/ST-VULN-003-swagger-api-docs-unauth.md

Credits

๐Ÿ” Vseen (VulDB User) VulDB CNA Team