logo

Faronics Insight Multiple Vulnerabilities

ID: ad2dc9a1-41d2-51da-bcb0-a3912fd61561

STIX ID: report--ad2dc9a1-41d2-51da-bcb0-a3912fd61561

Feed Name: NCC Research

Threat Score
78/100

Date Published: 2026-05-15

Date Updated: 2026-07-31

...
...

This technical advisory from NCC Group documents 11 vulnerabilities in Faronics Insight (teacher and student consoles) that enable high-impact attacks — including unauthenticated remote code execution as SYSTEM via file upload and DLL hijacking, zero-click XSS exploitation from artificial consoles, plaintext HTTP/WebSocket communications enabling MITM, world-readable plaintext keystroke logs, and insufficient access controls. The report includes detailed technical analysis, proof-of-concept exploit chains, CVE identifiers, and remediation recommendations; fixes were released in Insight v11.23.x.289.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.