CVE-2026-30707 Details
Description
An issue was discovered in SpeedExam Online Examination System (SaaS) after v.FEV2026. It allows Broken Access Control via the ReviewAnswerDetails ASP.NET PageMethod. Authenticated attackers can bypass client-side restrictions and invoke this method directly to retrieve the full answer key. The provider states that this issue is "Fixed in [02/2026] backend service update."
A broken access control vulnerability has been identified in SpeedExam Online Examination System (SaaS) versions after v.FEV2026. This vulnerability allows authenticated attackers to bypass client-side restrictions and directly invoke the 'ReviewAnswerDetails' ASP.NET PageMethod to access the full answer key. The issue arises from the exposure of administrative functions through ASP.NET AJAX PageMethods, which can be called without proper server-side validation of the user's exam status.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Mar 17, 2026CISA-ADP
Assessed Mar 18, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Maarckz/VulnReports/blob/main/CVE-2026-30707.md | [email protected] | ExploitTechnical Analysis |
| https://github.com/Maarckz/VulnReports/blob/main/SpeedExam%20%28SECOPS.GROUP%29.md | [email protected] | Broken Link |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| SpeedExam Online Examination System | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 24, 2026 | CVE Modified | [email protected] |
| Mar 18, 2026 | CVE Modified | CISA-ADP |
| Mar 17, 2026 | New CVE Received | [email protected] |
Volerion