CVE-2026-19853 PUBLISHED

CyberTutor|NewSiteServer (NSS) - Missing Authentication

Assigner: twcert
Reserved: 14.08.2026 Published: 24.08.2026 Updated: 24.08.2026

NewSiteServer (NSS) developed by CyberTutor has a Missing Authentication vulnerability. Unauthenticated remote attackers can exploit a specific functionality to send emails to anyone on behalf of the school.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor CyberTutor
Product NewSiteServer (NSS)
Versions Default: unaffected
  • Version all is affected

Solutions

Contact the vendor to take remedial measures.

References

Problem Types

  • CWE-306 Missing Authentication for Critical Function CWE

Impacts

  • CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs