Unrated severityNVD Advisory· Published Feb 6, 2026· Updated Feb 9, 2026
PlaciPy has a Hard-Coded Default Password for All Student Accounts (Account Takeover)
CVE-2026-25753
Description
PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application uses a hard-coded, static default password for all newly created student accounts. This results in mass account takeover, allowing any attacker to log in as any student once the password is known.
Affected products
2- Praskla-Technology/assessment-placipyv5Range: <= 1.0.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/Praskla-Technology/assessment-placipy/security/advisories/GHSA-6537-cf56-j9w2mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.