CVE-2019-17396: Powerschool Mobile
Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.
In the PowerSchool Mobile application 1.1.8 for Android, the username and password are stored in the log during authentication, and may be available to attackers via logcat.
Affected products
- Powerschool Powerschool Mobile: before 1.1.8 (fixed in 1.1.8)
Published 2019-10-15. Last modified 2026-06-17.