Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-88065— `tts-be` application has a Broken Access Control vulnerability

Quick assessment

Affected
NIAEFEUP tts-be
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

是一个为课程表选择器提供的后端服务,旨在帮助学生更好地选择课程安排。在 2.1.0 之前的版本中,多个 API 端点(如 和 )存在访问控制失效(Broken Access Control)漏洞。攻击者可以通过链式调用这些未认证的端点,将后端作为一个开放代理使用,从而绕过授权检查,能够枚举并提取来自上游大学系统的敏感个人身份信息(PII)。泄露的数据包括全名、学生 ID、课程表以及照片。该问题已在 2.1.0 版本中修复。

CVSS 7.5 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-88065

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
`tts-be` application has a Broken Access Control vulnerability
Source: CVE Program / CVE List V5
Vulnerability Description
`tts-be` is a backend for a timetable selector that aims to help students better choose their class schedules. Versions prior to 2.1.0 have a Broken Access Control vulnerability across several API endpoints (such as `/api/student/{id}/photo` and `/api/course_unit/{id}/exchange/metadata`). By chaining these unauthenticated endpoints, a remote attacker can use the backend as an open proxy to bypass authorization checks, allowing for the enumeration and extraction of sensitive Personally Identifiable Information (PII) from upstream university systems. The exposed data includes full names, student IDs, class schedules, and photos. This issue was fixed in version 2.1.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
信息暴露
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
NIAEFEUP tts-be < 2.1.0 -

II. Public POCs for CVE-2026-88065

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-88065

登录查看更多情报信息。

Vendor Advisories for CVE-2026-88065 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-88065

No comments yet


Leave a comment