CVE-2026-25811

CRITICAL

PlaciPy 1.0.0 - Incorrect Authorization via Email Domain Tenant Identifier

Title source: llm
STIX 2.1

Description

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application derives the tenant identifier directly from the email domain provided by the user, without validating domain ownership or registration. This allows cross-tenant data access.

References (1)

Core 1

Scores

CVSS v3 9.1
EPSS 0.0027
EPSS Percentile 18.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (1)
prasklatechnology/placipy 1.0.0
Published Feb 09, 2026
Tracked Since Feb 18, 2026