ctipilot.ch

Simple SA Wirtualna Uczelnia reflected XSS (locale parameter)

cve · CVE-2026-34907 single-source-national-cert

Coverage timeline
1
first 2026-06-05 → last 2026-06-05
Peak priority
high
1 high
Sources cited
2
2 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
1
see Related entities below
ATT&CK techniques
1
pinned v19.1 · see below

ATT&CK techniques

1 technique observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-06-05/cve-2026-34906-cve-2026-34907-simple-sa-wirtualna-uczelnia-u · ATT&CK page ↗

Story timeline

  1. 2026-06-05CVE-2026-34906 / CVE-2026-34907 — Simple SA "Wirtualna Uczelnia": unauthenticated SSTI-to-RCE in the student-administration platform used across Polish public universities
    trending-vulnerabilitiesCVE-2026-34906 / CVE-2026-34907 — Simple SA "Wirtualna Uczelnia": unauthenticated SSTI-to-RCE in the student-administration platform used across Polish public

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • cert.pl1 (50%)
  • zeroday.cloud1 (50%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Simple SA Wirtualna Uczelnia reflected XSS (locale parameter) (1)

2026-06-05 · view entry permalink →

CVE-2026-34906 / CVE-2026-34907 — Simple SA "Wirtualna Uczelnia": unauthenticated SSTI-to-RCE in the student-administration platform used across Polish public universities

CERT Polska published a coordinated-disclosure advisory for Wirtualna Uczelnia ("Virtual University"), a proprietary higher-education administration platform by Simple SA deployed across Polish universities (CERT Polska, 2026-06-02). CVE-2026-34906 is a Server-Side Template Injection in the redirectToUrl endpoint: insufficient validation of the redirect-URL parameter lets an unauthenticated attacker inject template expressions that execute on the server, reaching remote code execution (T1190, CWE-1336). CVE-2026-34907 is a companion reflected XSS via the locale parameter. Both affect all versions through build wu#2016.437.295#0#20260327_105545; CERT Polska records the finding from Dawid Bakaj (VIPentest) and no vendor patch or fixed version had been published at disclosure, and no in-the-wild exploitation is reported. As the national CERT and primary disclosing party, CERT Polska is the sole source (national-CERT carve-out, PD-5).

Why it matters to us: a pre-auth RCE in a public-facing student portal is a foothold into university networks and a trove of academic identity data — the EU public-sector education sector the brief tracks. Until Simple SA ships a fix, restrict the redirectToUrl endpoint to internal/authenticated sources at the reverse proxy or WAF, and hunt web-server access logs for template metacharacters (${...}, #{...}, {{...}}) in the redirect parameter.

CVE Summary Table

CVE Product CVSS EPSS KEV Exploited Patch Source
CVE-2026-23479 Redis 7.2.0–7.2.13, 7.4.x, 8.2.x, 8.4.x, 8.6.x 8.8 (3.1) / 7.7 (4.0) n/a No No (public PoC chain) 7.2.14 / 7.4.9 / 8.2.6 / 8.4.3 / 8.6.3 (2026-05-05) ZeroDay.Cloud
CVE-2026-34906 Simple SA Wirtualna Uczelnia (SSTI RCE) n/a n/a No No None at disclosure CERT Polska
CVE-2026-34907 Simple SA Wirtualna Uczelnia (reflected XSS) n/a n/a No No None at disclosure CERT Polska
vulnerability05 Jun 05:00Zsingle-source · national CERTOpen finding ↗