CVE-2026-75460

XueZhiSi Open Source Exam System <= 3.9.0 has a privilege escalation vulnerability in the teacher-end interface POST /api/teacher/user/page/list. The role parameter in UserPageRequestVM is fully controllable by the requester.

  • Published Aug 31, 2026
  • CVSS 6.5 medium
  • 0.3% chance of exploitation in the next 30 days (EPSS)

CVE-2026-75460 at the National Vulnerability Database