---
schema: 1
kind: vulnerability
title: "CVE-2026-34906 / CVE-2026-34907 — Simple SA \"Wirtualna Uczelnia\": unauthenticated SSTI-to-RCE in the student-administration platform used across Polish public universities"
headline: "CVE-2026-34906 / CVE-2026-34907 — Simple SA \"Wirtualna Uczelnia\": unauthenticated SSTI-to-RCE in the student-administration platform used across Polish public"
summary: "CERT Polska disclosed an unauthenticated SSTI-to-RCE in Wirtualna Uczelnia, the student-administration platform across Polish public universities (CVE-2026-34906) — no vendor patch published at disclosure. EU public-sector education software with a pre-auth foothold path (CERT Polska, 2026-06-02)."
discovered_at: "2026-06-05T05:00:04Z"
event_date: 2026-06-02
run_id: 2026-06-05-2c6574c4
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - rce
  - pre-auth
  - no-patch
regions:
  - europe
sectors:
  - education
  - public-sector
entities: []
cves:
  - id: CVE-2026-34906
    cvss: n
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - no-patch
  - id: CVE-2026-34907
    cvss: a
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - no-patch
sources:
  - url: "https://cert.pl/en/posts/2026/06/CVE-2026-34906/"
    publisher: "CERT Polska, 2026-06-02"
    role: primary
closed_sources: []
evidence: []
verification: single-source-national-cert
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions: []
migrated_from: briefs/2026-06-05.md
---

CERT Polska published a coordinated-disclosure advisory for **Wirtualna Uczelnia** ("Virtual University"), a proprietary higher-education administration platform by Simple SA deployed across Polish universities ([CERT Polska, 2026-06-02](https://cert.pl/en/posts/2026/06/CVE-2026-34906/)). **CVE-2026-34906** is a Server-Side Template Injection in the `redirectToUrl` endpoint: insufficient validation of the redirect-URL parameter lets an unauthenticated attacker inject template expressions that execute on the server, reaching remote code execution (`T1190`, CWE-1336). **CVE-2026-34907** is a companion reflected XSS via the locale parameter. Both affect all versions through build `wu#2016.437.295#0#20260327_105545`; CERT Polska records the finding from Dawid Bakaj (VIPentest) and **no vendor patch or fixed version had been published at disclosure**, and no in-the-wild exploitation is reported. As the national CERT and primary disclosing party, CERT Polska is the sole source (national-CERT carve-out, PD-5).

**Why it matters to us:** a pre-auth RCE in a public-facing student portal is a foothold into university networks and a trove of academic identity data — the EU public-sector education sector the brief tracks. Until Simple SA ships a fix, restrict the `redirectToUrl` endpoint to internal/authenticated sources at the reverse proxy or WAF, and hunt web-server access logs for template metacharacters (`${...}`, `#{...}`, `{{...}}`) in the redirect parameter.


#### CVE Summary Table

| CVE | Product | CVSS | EPSS | KEV | Exploited | Patch | Source |
|---|---|---|---|---|---|---|---|
| CVE-2026-23479 | Redis 7.2.0–7.2.13, 7.4.x, 8.2.x, 8.4.x, 8.6.x | 8.8 (3.1) / 7.7 (4.0) | n/a | No | No (public PoC chain) | 7.2.14 / 7.4.9 / 8.2.6 / 8.4.3 / 8.6.3 (2026-05-05) | [ZeroDay.Cloud](https://www.zeroday.cloud/blog/redis-cve-2026-23479-deep-dive) |
| CVE-2026-34906 | Simple SA Wirtualna Uczelnia (SSTI RCE) | n/a | n/a | No | No | None at disclosure | [CERT Polska](https://cert.pl/en/posts/2026/06/CVE-2026-34906/) |
| CVE-2026-34907 | Simple SA Wirtualna Uczelnia (reflected XSS) | n/a | n/a | No | No | None at disclosure | [CERT Polska](https://cert.pl/en/posts/2026/06/CVE-2026-34906/) |
