CVE-2026-86275
A vulnerability was detected in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This vulnerability affects the function register of the file auth.php. Performing a manipulation of the argument role results in improper privilege management. Remote exploitation of the attack is possible. The exploit is now public and may be used.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.9
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 0.29%
- CWE
- CWE-269, CWE-266
- Published
- 2026-09-07
- Last modified
- 2026-09-08
Affected products
- SourceCodester Syllabus-Aligned Learning Management & Examination System
Weakness type
Related vulnerabilities
- CVE-2026-88891 — OpenPanel Read-Only Access Level Enforcement Bypass via Mutations
- CVE-2026-88863 — capgo.app through 12.207.1 Privilege Escalation via invite_new_user_to_org
- CVE-2026-84042 — Crun: crun: rootful krun with passt executes container payload as host root
- CVE-2026-87998 — Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion
- CVE-2026-86746 — Snipe-IT before 8.7.0 Authorization Bypass via Livewire Snapshot Replay
- CVE-2026-12858 — Local privilege escalation vulnerability in ESET AV Remover
- CVE-2026-14359 — YITH WooCommerce Waitlist Premium <= 3.35.0 - Authenticated (Subscriber+) Privilege Escalation to Admin via wp_ajax_yith_wcwtl_add_user
- CVE-2026-75927 — PublishPress Capabilities <= 2.50.0 - Authenticated (Editor+) Privilege Escalation to Fresh-Install Default Capability Grant