What is CVE-2026-19784?
An authorization bypass vulnerability exists in the DBUpdate function within the Discipline/Referrals.php file in RosarioSIS up to version 12.8. This flaw allows remote attacks, and an exploit has been publicly disclosed. It is strongly recommended to upgrade to version 12.9 immediately to mitigate the risk.
Azərbaycanca: RosarioSIS 12.8 versiyasına qədər olan sistemlərdə Discipline/Referrals.php faylındakı DBUpdate funksiyasında avtorizasiyadan yan keçmə zəifliyi aşkarlanıb. Bu boşluq uzaqdan hücum etməyə imkan verir və istismar kodu artıq ictimaiyyətə açıqdır. Təsirə məruz qalmamaq üçün 12.9 versiyasına təcili yeniləmək tövsiyə olunur.
FAQ2
Which versions of RosarioSIS are affected by CVE-2026-19784 and how can it be mitigated?
This vulnerability affects RosarioSIS up to version 12.8. It is strongly recommended to upgrade to version 12.9 immediately to mitigate the risk.
Is remote exploitation possible for CVE-2026-19784?
Yes, this flaw allows remote attacks, and an exploit has been publicly disclosed.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.