High severity8.1NVD Advisory· Published May 2, 2026· Updated May 5, 2026
CVE-2026-7491
CVE-2026-7491
Description
School App developed by Zyosoft has an Insecure Direct Object Reference vulnerability, allowing authenticated remote attackers to modify a specific parameter to read and modify other users' data.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.