Critical severity9.1NVD Advisory· Published Feb 9, 2026· Updated Jun 17, 2026
CVE-2026-25811
CVE-2026-25811
Description
PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application derives the tenant identifier directly from the email domain provided by the user, without validating domain ownership or registration. This allows cross-tenant data access.
Affected products
3- cpe:2.3:a:prasklatechnology:placipy:1.0.0:*:*:*:*:*:*:*
- Range: <1.0.0
- Praskla-Technology/assessment-placipyv5Range: = 1.0.0
Patches
Vulnerability mechanics
References
1- github.com/Praskla-Technology/assessment-placipy/security/advisories/GHSA-3gmm-9ww2-87fhnvdMitigationVendor Advisory
News mentions
0No linked articles in our index yet.