Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-97878— zhistaredu StarTraining Druid Console index.html anonymous missing authentication

Quick assessment

Affected
zhistaredu StarTraining
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 zhistaredu StarTraining 3.8.1 及更早版本中,发现了一个安全漏洞。受影响的组件 Druid Console 中的文件 /druid/index.html 包含一个名为 anonymous 的函数,该函数存在身份验证缺失的问题。此类漏洞可导致未经授权的系统访问,攻击者可以从远程发起攻击。目前该漏洞的利用代码已在公开渠道发布,可能被恶意利用。开发厂商在漏洞披露初期已收到通知,但至今未作出任何回应。

CVSS 7.3 · High EPSS 0.63% · P48
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-97878

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
zhistaredu StarTraining Druid Console index.html anonymous missing authentication
Source: CVE Program / CVE List V5
Vulnerability Description
A vulnerability was identified in zhistaredu StarTraining up to 3.8.1. Impacted is the function anonymous of the file /druid/index.html of the component Druid Console. Such manipulation leads to missing authentication. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
关键功能的认证机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
zhistaredu StarTraining 3.8.0 cpe:2.3:a:zhistaredu:startraining:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-97878

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-97878

请登录查看更多情报信息。

Other References for CVE-2026-97878 (5)

Same Patch Batch · zhistaredu · 2026-09-25 · 3 CVEs total

CVE-2026-97877 7.3 HIGH zhistaredu StarTraining JWT Token application.yml UserLoginService.createToken hard-coded
CVE-2026-97879 5.3 MEDIUM zhistaredu StarTraining api-docs Endpoint SecurityConfig.java missing authentication

IV. Related Vulnerabilities

V. Comments for CVE-2026-97878

No comments yet


Leave a comment