CVE-2026-30707
Last modified
CVE-2026-30707 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. An issue was discovered in SpeedExam Online Examination System (SaaS) after v.FEV2026. It allows Broken Access Control via the ReviewAnswerDetails ASP.NET PageMethod. EPSS estimates a 0.33% chance of exploitation in the next 30 days.
Description
An issue was discovered in SpeedExam Online Examination System (SaaS) after v.FEV2026. It allows Broken Access Control via the ReviewAnswerDetails ASP.NET PageMethod. Authenticated attackers can bypass client-side restrictions and invoke this method directly to retrieve the full answer key. The provider states that this issue is "Fixed in [02/2026] backend service update."
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-30707?
How severe is CVE-2026-30707?
How do I fix CVE-2026-30707?
Are you affected by CVE-2026-30707?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
