Wirtualna Uczelnia SSTI Flaw Enables Unauthenticated RCE
Unauthenticated attackers can achieve remote code execution via a server-side template injection flaw in Wirtualna Uczelnia's redirectToUrl endpoint.
CERT Polska coordinated disclosure of two vulnerabilities in Wirtualna Uczelnia, a university management software platform. The most severe, CVE-2026-34906, is a Server-Side Template Injection flaw in the redirectToUrl endpoint's redirectUrlParameter parameter. Insufficient input validation allows an unauthenticated attacker to inject arbitrary template expressions that execute on the server, potentially enabling remote command execution and reverse shell access.
A second, lower-severity issue, CVE-2026-34907, is a reflected Cross-Site Scripting vulnerability affecting the locale parameter across multiple endpoints. An attacker can craft a malicious URL embedding JavaScript in the locale parameter; when a victim opens the link, the script executes in their browser context. Both vulnerabilities affect Wirtualna Uczelnia versions up to build wu#2016.437.295#0#20260327_105545.
No evidence of active exploitation is noted in the advisory; this is a coordinated disclosure resulting from a report by an independent researcher. Organizations using Wirtualna Uczelnia, primarily educational institutions, should apply vendor patches once available and monitor for updates from CERT Polska.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/06/CVE-2026-34906
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free