CVE-2026-89178 Details
Description
WeenyGenius, a computer lab management system by Howyar Technologies, has an Origin Validation Error vulnerability. Unauthenticated attackers on the same network can spoof the teacher workstation and send broadcast packets, causing student computers to attempt to establish a connection with the attacker.
An origin validation error vulnerability has been identified in WeenyGenius, a computer lab management system by Howyar Technologies, affecting versions through 12.2.031. This vulnerability allows unauthenticated attackers on the same network to spoof a teacher's workstation. By sending broadcast packets, attackers can cause student computers to attempt to connect with them, potentially leading to unauthorized access or control over the student endpoints.
Users are advised to update WeenyGenius to version 12.3.033 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 11, 2026CISA-ADP
Assessed Sep 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.twcert.org.tw/en/cp-139-11200-ffc3c-2.html | [email protected] | AdvisoryBundleRemedy |
| https://www.twcert.org.tw/tw/cp-132-11201-658c0-1.html | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-940 | Improper Verification of Source of a Communication Channel | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Howyar Technologies WeenyGenius | <= 12.2.031 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 11, 2026 | CVE Modified | CISA-ADP |
| Sep 11, 2026 | New CVE Received | [email protected] |
Volerion