2026 Ravenna Hub — IDOR exposed 1.63M+ student records
Data compromised
Children's names, DOB, addresses, pictures, school details; parent emails, phone numbers
Technical writeup
A student admissions website used by thousands of schools had an insecure direct object reference (IDOR) vulnerability. Any logged-in user could access personally identifiable data of other users by modifying the student profile number in the URL. Exposed data included children's names, dates of birth, addresses, pictures, school details, and parent email/phone. VenturEd Solutions fixed the bug on February 19, 2026 after TechCrunch disclosure. Over 1.63 million records were potentially accessible.
Root cause
IDOR vulnerability; weak access controls on student profile numbers