ctipilot.ch
← Back to Daily brief 2026-06-05
HIGHCVE-2026-34906 +1vulnerability

CVE-2026-34906 / CVE-2026-34907 — Simple SA "Wirtualna Uczelnia": unauthenticated SSTI-to-RCE in the student-administration platform used across Polish public universities

discovered 2026-06-05 05:00 UTCrun 2026-06-05-2c6574c41 sourcesingle-source · national CERT

CERT Polska published a coordinated-disclosure advisory for Wirtualna Uczelnia ("Virtual University"), a proprietary higher-education administration platform by Simple SA deployed across Polish universities (CERT Polska, 2026-06-02). CVE-2026-34906 is a Server-Side Template Injection in the redirectToUrl endpoint: insufficient validation of the redirect-URL parameter lets an unauthenticated attacker inject template expressions that execute on the server, reaching remote code execution (T1190, CWE-1336). CVE-2026-34907 is a companion reflected XSS via the locale parameter. Both affect all versions through build wu#2016.437.295#0#20260327_105545; CERT Polska records the finding from Dawid Bakaj (VIPentest) and no vendor patch or fixed version had been published at disclosure, and no in-the-wild exploitation is reported. As the national CERT and primary disclosing party, CERT Polska is the sole source (national-CERT carve-out, PD-5).

Why it matters to us: a pre-auth RCE in a public-facing student portal is a foothold into university networks and a trove of academic identity data — the EU public-sector education sector the brief tracks. Until Simple SA ships a fix, restrict the redirectToUrl endpoint to internal/authenticated sources at the reverse proxy or WAF, and hunt web-server access logs for template metacharacters (${...}, #{...}, {{...}}) in the redirect parameter.

CVE Summary Table

CVE Product CVSS EPSS KEV Exploited Patch Source
CVE-2026-23479 Redis 7.2.0–7.2.13, 7.4.x, 8.2.x, 8.4.x, 8.6.x 8.8 (3.1) / 7.7 (4.0) n/a No No (public PoC chain) 7.2.14 / 7.4.9 / 8.2.6 / 8.4.3 / 8.6.3 (2026-05-05) ZeroDay.Cloud
CVE-2026-34906 Simple SA Wirtualna Uczelnia (SSTI RCE) n/a n/a No No None at disclosure CERT Polska
CVE-2026-34907 Simple SA Wirtualna Uczelnia (reflected XSS) n/a n/a No No None at disclosure CERT Polska

ATT&CK mapping

1 technique mapped from the cited reporting · MITRE ATT&CK v19.2

Initial Access TA0001
T1190Exploit Public-Facing Application

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

overlap matrix · ATT&CK page ↗

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.