CVE-2026-30707
High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.
An issue was discovered in SpeedExam Online Examination System (SaaS) after v.FEV2026. It allows Broken Access Control via the ReviewAnswerDetails ASP.NET PageMethod. Authenticated attackers can bypass client-side restrictions and invoke this method directly to retrieve the full answer key. The provider states that this issue is "Fixed in [02/2026] backend service update."
Published 2026-03-17. Last modified 2026-06-17.