Academic Exposure: The Unpatched Flaw Siphoning Student Data from DRC INSIGHT
ID: ad7d3a49-86d3-5adc-9406-bcf3e9665cc4
STIX ID: report--ad7d3a49-86d3-5adc-9406-bcf3e9665cc4
Feed Name: securityonline.info
A critical vulnerability (CVE-2026-5756) in DRC INSIGHT's Central Office Services component exposes the /v0/configuration administrative endpoint without authentication, allowing any device on the same network to overwrite configuration JSON. An attacker could redirect student data and audio to an attacker-controlled server, force HTTPS traffic through a malicious proxy to intercept communications, or crash the service to halt exams; no patch is available and administrators are advised to isolate the server, firewall the endpoint, monitor outbound traffic, and verify config integrity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
