CVE-2026-25811

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application derives the tenant identifier directly from the email domain provided by the user, without validating domain ownership or registration. This allows cross-tenant data access.
Configurations

Configuration 1 (hide)

cpe:2.3:a:prasklatechnology:placipy:1.0.0:*:*:*:*:*:*:*

History

18 Feb 2026, 20:30

Type Values Removed Values Added
CPE cpe:2.3:a:prasklatechnology:placipy:1.0.0:*:*:*:*:*:*:*
First Time Prasklatechnology
Prasklatechnology placipy
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1
References () https://github.com/Praskla-Technology/assessment-placipy/security/advisories/GHSA-3gmm-9ww2-87fh - () https://github.com/Praskla-Technology/assessment-placipy/security/advisories/GHSA-3gmm-9ww2-87fh - Mitigation, Vendor Advisory
Summary
  • (es) PlaciPy es un sistema de gestión de prácticas diseñado para instituciones educativas. En la versión 1.0.0, la aplicación deriva el identificador de inquilino directamente del dominio de correo electrónico proporcionado por el usuario, sin validar la propiedad o el registro del dominio. Esto permite el acceso a datos entre inquilinos.

09 Feb 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-09 22:16

Updated : 2026-02-18 20:30


NVD link : CVE-2026-25811

Mitre link : CVE-2026-25811

CVE.ORG link : CVE-2026-25811


JSON object : View

Products Affected

prasklatechnology

  • placipy
CWE
CWE-863

Incorrect Authorization