CVE-2026-8890
Auth bypass in Mobile API enables unauthenticated impersonation via crafted g header.
Is CVE-2026-8890 being exploited?
Not confirmed. CVE-2026-8890 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.49% probability of exploitation in the next 30 days.
How severe is CVE-2026-8890?
CVE-2026-8890 is rated High with a CVSS score of 8.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-8890?
Not known from our data. No patch reference has been recorded for CVE-2026-8890, which is not the same as no patch existing — a fix may have shipped without a tagged reference, or after this record was written. The vendor advisory is the only authority on whether a fix exists, and mitigations may be available regardless.
What does CVE-2026-8890 affect?
CVE-2026-8890 affects code100x Mobile API. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-8890?
Validate Auth-Key and bind identity server-side; reject spoofed g header.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Unauthenticated impersonation via crafted g header exposes any enrolled user's (or admin's) course data.
Immediate action required
- affected< 90b489ee7c63c301107d6374d4b3f2b8e4060fe5
- affected< 88c6c5e94e23da101235c4c7e9c7591ac1016549
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.