Ravenna Hub Fixes Vulnerability Exposing Student Data

Ravenna Hub Fixes Vulnerability Exposing Student Data

First seen 21 Feb 2026, 21:11 UTC TechcrunchScworld 30.8

Article Content

Browse articles
ThreatCluster

Ravenna Hub, a student admissions website, fixed a vulnerability that exposed personal information of children and their families. The issue allowed any logged-in user to access sensitive data associated with other users, including names, dates of birth, and addresses. The vulnerability was identified as an insecure direct object reference (IDOR).

Timeline

2026-02-19
TechCrunch reports on data exposure vulnerability
2026-02-21
Scworld reports that Ravenna Hub has fixed the vulnerability