← Ravenna Hub

2026 Ravenna Hub — IDOR exposed 1.63M+ student records

2026 1.6M records affected Share on X

Data compromised

Children's names, DOB, addresses, pictures, school details; parent emails, phone numbers

Technical writeup

A student admissions website used by thousands of schools had an insecure direct object reference (IDOR) vulnerability. Any logged-in user could access personally identifiable data of other users by modifying the student profile number in the URL. Exposed data included children's names, dates of birth, addresses, pictures, school details, and parent email/phone. VenturEd Solutions fixed the bug on February 19, 2026 after TechCrunch disclosure. Over 1.63 million records were potentially accessible.

Root cause

IDOR vulnerability; weak access controls on student profile numbers

References