CVE-2026-3110 describes an Insecure Direct Object Reference (IDOR) vulnerability within Campus Educativa, specifically affecting the user data export functionality. This flaw permits an unauthenticated attacker to access sensitive user information, such as names, emails, and phone numbers, by brute-forcing course IDs through a manipulated URL. With a CVSSv4 score of 8.7 (HIGH), it presents a significant confidentiality risk due to its network attack vector and low attack complexity. There is currently no indication of active exploitation, public exploit code, or widespread community discussion, and it is not present in CISA's Known Exploited Vulnerabilities catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Educativa | Campus | 14.05.00-35CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.