CVE-2026-25811

P

laciPy is a placement management system designed for educational institutions. In version 1.0.0, the application derives the tenant identifier directly from the email domain provided by the user, without validating domain ownership or registration. This allows cross-tenant data access.

Configurations

Configuration 1 (hide)

cpe:2.3:a:prasklatechnology:placipy:1.0.0:*:*:*:*:*:*:*

History

18 Feb 2026, 20:30

Type Values Removed Values Added
CPE cpe:2.3:a:prasklatechnology:placipy:1.0.0:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1
First Time Prasklatechnology
Prasklatechnology placipy
Summary
  • (es) PlaciPy es un sistema de gestión de prácticas diseñado para instituciones educativas. En la versión 1.0.0, la aplicación deriva el identificador de inquilino directamente del dominio de correo electrónico proporcionado por el usuario, sin validar la propiedad o el registro del dominio. Esto permite el acceso a datos entre inquilinos.
References () https://github.com/Praskla-Technology/assessment-placipy/security/advisories/GHSA-3gmm-9ww2-87fh - () https://github.com/Praskla-Technology/assessment-placipy/security/advisories/GHSA-3gmm-9ww2-87fh - Mitigation, Vendor Advisory

09 Feb 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-09 22:16

Updated : 2026-02-18 20:30


NVD link : CVE-2026-25811

Mitre link : CVE-2026-25811

CVE.ORG link : CVE-2026-25811


JSON object : View

Products Affected
CWE
CWE-863

Incorrect Authorization