CVE-2026-24900 | MarkUsProject Markus up to 2.9.0 html_content select_file_id authorization
A vulnerability classified as problematic was found in MarkUsProject Markus up to 2.9.0. Affected by this issue is some unknown functionality of the file courses//assignments//submissions/html_content. Executing a manipulation of the argument select_file_id can lead to authorization bypass.
This vulnerability is handled as CVE-2026-24900. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.